Microsoft Outlook vulnerabilities
106 known vulnerabilities affecting microsoft/outlook.
Total CVEs
106
CISA KEV
5
actively exploited
Public exploits
18
Exploited in wild
6
Severity breakdown
CRITICAL11HIGH52MEDIUM43
Vulnerabilities
Page 5 of 6
CVE-2017-8545P4MEDIUMCVSS 6.5v20162017-06-15
CVE-2017-8545 [MEDIUM] CWE-20 CVE-2017-8545: A spoofing vulnerability exists in when Microsoft Outlook for Mac does not sanitize html properly, a
A spoofing vulnerability exists in when Microsoft Outlook for Mac does not sanitize html properly, aka "Microsoft Outlook for Mac Spoofing Vulnerability".
nvd
CVE-2013-3905P4MEDIUMCVSS 5.0v2007v2010+1 more2013-11-13
CVE-2013-3905 [MEDIUM] CWE-200 CVE-2013-3905: Microsoft Outlook 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT does not properly expand metadata co
Microsoft Outlook 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT does not properly expand metadata contained in S/MIME certificates, which allows remote attackers to obtain sensitive network configuration and state information via a crafted certificate in an e-mail message, aka "S/MIME AIA Vulnerability."
nvd
CVE-2002-2101P4HIGHCVSS 7.5v20022002-12-31
CVE-2002-2101 [HIGH] CVE-2002-2101: Microsoft Outlook 2002 allows remote attackers to execute arbitrary JavaScript code, even when scrip
Microsoft Outlook 2002 allows remote attackers to execute arbitrary JavaScript code, even when scripting is disabled, via an "about:" or "javascript:" URI in the href attribute of an "a" tag.
nvd
CVE-2006-2055P4MEDIUMCVSS 5.0v20032006-04-26
CVE-2006-2055 [MEDIUM] CWE-88 CVE-2006-2055: Argument injection vulnerability in Microsoft Outlook 2003 SP1 allows user-assisted remote attackers
Argument injection vulnerability in Microsoft Outlook 2003 SP1 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment. NOTE: it is not clear whether this issue
nvd
CVE-2020-1493P4MEDIUMCVSS 5.5v2010v2013+1 more2020-08-17
CVE-2020-1493 [MEDIUM] CWE-922 CVE-2020-1493: An information disclosure vulnerability exists when attaching files to Outlook messages. This vulner
An information disclosure vulnerability exists when attaching files to Outlook messages. This vulnerability could potentially allow users to share attached files such that they are accessible by anonymous users where they should be restricted to specific users.
To exploit this vulnerability, an attacker would have to attach a file as a link to an emai
nvd
CVE-2017-17689P4MEDIUMCVSS 5.9v2007v2010+2 more2018-05-16
CVE-2017-17689 [MEDIUM] CVE-2017-17689: The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can in
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
nvd
CVE-2017-8572P4MEDIUMCVSS 5.5v2007v2010+2 more2017-08-01
CVE-2017-8572 [MEDIUM] CWE-200 CVE-2017-8572: Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 201
Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 2016 as packaged in Microsoft Office allows an information disclosure vulnerability due to the way that it discloses the contents of its memory, aka "Microsoft Office Outlook Information Disclosure Vulnerability".
nvd
CVE-2001-0145P4HIGHCVSS 7.5v98v20002001-05-03
CVE-2001-0145 [HIGH] CVE-2001-0145: Buffer overflow in VCard handler in Outlook 2000 and 98, and Outlook Express 5.x, allows an attacker
Buffer overflow in VCard handler in Outlook 2000 and 98, and Outlook Express 5.x, allows an attacker to execute arbitrary commands via a malformed vCard birthday field.
nvd
CVE-2004-2482P4MEDIUMCVSS 5.0v2000v20032004-12-31
CVE-2004-2482 [MEDIUM] CVE-2004-2482: Microsoft Outlook 2000 and 2003, when configured to use Microsoft Word 2000 or 2003 as the e-mail ed
Microsoft Outlook 2000 and 2003, when configured to use Microsoft Word 2000 or 2003 as the e-mail editor and when forwarding e-mail, does not properly handle an opening OBJECT tag that does not have a closing OBJECT tag, which causes Outlook to automatically download the URI in the data property of the OBJECT tag and might allow remote attackers to execute ar
nvd
CVE-2019-0560P4MEDIUMCVSS 5.5v2010-sp2v2013-sp1+1 more2019-01-08
CVE-2019-0560 [MEDIUM] CVE-2019-0560: An information disclosure vulnerability exists when Microsoft Office improperly discloses the conten
An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, aka "Microsoft Office Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office.
nvd
CVE-2017-8508P4MEDIUMCVSS 5.5v2007v2010+2 more2017-06-15
CVE-2017-8508 [MEDIUM] CVE-2017-8508: A security feature bypass vulnerability exists in Microsoft Office software when it improperly handl
A security feature bypass vulnerability exists in Microsoft Office software when it improperly handles the parsing of file formats, aka "Microsoft Office Security Feature Bypass Vulnerability".
nvd
CVE-2006-1305P4MEDIUMCVSS 4.3v2000v2002+1 more2006-12-31
CVE-2006-1305 [MEDIUM] CWE-399 CVE-2006-1305: Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to cause a denial of se
Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to cause a denial of service (memory exhaustion and interrupted mail recovery) via malformed e-mail header information, possibly related to (1) long subject lines or (2) large numbers of recipients in To or CC headers.
nvd
CVE-2019-1204P4MEDIUMCVSS 4.3v2010v2013+1 more2019-08-14
CVE-2019-1204 [MEDIUM] CWE-20 CVE-2019-1204: An elevation of privilege vulnerability exists when Microsoft Outlook initiates processing of incomi
An elevation of privilege vulnerability exists when Microsoft Outlook initiates processing of incoming messages without sufficient validation of the formatting of the messages. An attacker who successfully exploited the vulnerability could attempt to force Outlook to load a local or remote message store (over SMB).
To exploit the vulnerability, the att
nvd
CVE-2004-0503P4MEDIUMCVSS 5.0v20032004-08-18
CVE-2004-0503 [MEDIUM] CVE-2004-0503: Microsoft Outlook 2003 allows remote attackers to bypass the default zone restrictions and execute s
Microsoft Outlook 2003 allows remote attackers to bypass the default zone restrictions and execute script within media files via a Rich Text Format (RTF) message containing an OLE object for the Windows Media Player, which bypasses Media Player's setting to disallow scripting and may lead to unprompted installation of an executable when exploited in conjuncti
nvd
CVE-2005-1052P4MEDIUMCVSS 5.0v20032005-05-02
CVE-2005-1052 [MEDIUM] CVE-2005-1052: Microsoft Outlook 2003 and Outlook Web Access (OWA) 2003 do not properly display comma separated add
Microsoft Outlook 2003 and Outlook Web Access (OWA) 2003 do not properly display comma separated addresses in the From field in an e-mail message, which could allow remote attackers to spoof e-mail addresses.
nvd
CVE-2002-0481P4MEDIUMCVSS 5.1v20022002-08-12
CVE-2002-0481 [MEDIUM] CVE-2002-0481: An interaction between Windows Media Player (WMP) and Outlook 2002 allows remote attackers to bypass
An interaction between Windows Media Player (WMP) and Outlook 2002 allows remote attackers to bypass Outlook security settings and execute Javascript via an IFRAME in an HTML email message that references .WMS (Windows Media Skin) or other WMP media files, whose onload handlers execute the player.LaunchURL() Javascript function.
nvd
CVE-1999-1164P4MEDIUMCVSS 5.0v97v98+1 more1999-06-25
CVE-1999-1164 [MEDIUM] CVE-1999-1164: Microsoft Outlook client allows remote attackers to cause a denial of service by sending multiple em
Microsoft Outlook client allows remote attackers to cause a denial of service by sending multiple email messages with the same X-UIDL headers, which causes Outlook to hang.
nvd
CVE-2002-2100P4MEDIUMCVSS 5.0v2000v20022002-12-31
CVE-2002-2100 [MEDIUM] CVE-2002-2100: Microsoft Outlook 2002 allows remote attackers to embed bypass the file download restrictions for at
Microsoft Outlook 2002 allows remote attackers to embed bypass the file download restrictions for attachments via an HTML email message that uses an IFRAME to reference malicious content.
nvd
CVE-2004-0284P4MEDIUMCVSS 5.0v2002v20032004-11-23
CVE-2004-0284 [MEDIUM] CVE-2004-0284: Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a de
Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%00) after the host name.
nvd
CVE-2002-1255P4MEDIUMCVSS 5.0v20022002-12-18
CVE-2002-1255 [MEDIUM] CVE-2002-1255: Microsoft Outlook 2002 allows remote attackers to cause a denial of service (repeated failure) via a
Microsoft Outlook 2002 allows remote attackers to cause a denial of service (repeated failure) via an email message with a certain invalid header field that is accessed using POP3, IMAP, or WebDAV, aka "E-mail Header Processing Flaw Could Cause Outlook 2002 to Fail."
nvd