cbcvebase.

Microsoft Outlook vulnerabilities

111 known vulnerabilities affecting microsoft/outlook.

Total CVEs
111
CISA KEV
5
actively exploited
Public exploits
18
Exploited in wild
6
Severity breakdown
CRITICAL11HIGH55MEDIUM45

Vulnerabilities

Page 5 of 6
CVE-2024-43482P3MEDIUMCVSS 6.5fixed in 4.2435.02024-09-10
CVE-2024-43482 [MEDIUM] CWE-285 CVE-2024-43482: Microsoft Outlook for iOS Information Disclosure Vulnerability Microsoft Outlook for iOS Information Disclosure Vulnerability
nvd
CVE-2025-21357P4MEDIUMCVSS 6.7v20162025-01-14
CVE-2025-21357 [MEDIUM] CWE-908 CVE-2025-21357: Microsoft Outlook Remote Code Execution Vulnerability Microsoft Outlook Remote Code Execution Vulnerability
nvd
CVE-2000-0621P4HIGHCVSS 7.5v97v98+1 more2000-07-20
CVE-2000-0621 [HIGH] CVE-2000-0621: Microsoft Outlook 98 and 2000, and Outlook Express 4.0x and 5.0x, allow remote attackers to read fil Microsoft Outlook 98 and 2000, and Outlook Express 4.0x and 5.0x, allow remote attackers to read files on the client's system via a malformed HTML message that stores files outside of the cache, aka the "Cache Bypass" vulnerability.
nvd
CVE-2017-8545P4MEDIUMCVSS 6.5v20162017-06-15
CVE-2017-8545 [MEDIUM] CWE-20 CVE-2017-8545: A spoofing vulnerability exists in when Microsoft Outlook for Mac does not sanitize html properly, a A spoofing vulnerability exists in when Microsoft Outlook for Mac does not sanitize html properly, aka "Microsoft Outlook for Mac Spoofing Vulnerability".
nvd
CVE-2013-3905P4MEDIUMCVSS 5.0v2007v2010+1 more2013-11-13
CVE-2013-3905 [MEDIUM] CWE-200 CVE-2013-3905: Microsoft Outlook 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT does not properly expand metadata co Microsoft Outlook 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT does not properly expand metadata contained in S/MIME certificates, which allows remote attackers to obtain sensitive network configuration and state information via a crafted certificate in an e-mail message, aka "S/MIME AIA Vulnerability."
nvd
CVE-2002-2101P4HIGHCVSS 7.5v20022002-12-31
CVE-2002-2101 [HIGH] CVE-2002-2101: Microsoft Outlook 2002 allows remote attackers to execute arbitrary JavaScript code, even when scrip Microsoft Outlook 2002 allows remote attackers to execute arbitrary JavaScript code, even when scripting is disabled, via an "about:" or "javascript:" URI in the href attribute of an "a" tag.
nvd
CVE-2003-1048P4HIGHCVSS 7.8v20002004-07-27
CVE-2003-1048 [HIGH] CWE-415 CVE-2003-1048: Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.
nvd
CVE-2020-1493P4MEDIUMCVSS 5.5v2010v2013+1 more2020-08-17
CVE-2020-1493 [MEDIUM] CWE-922 CVE-2020-1493: An information disclosure vulnerability exists when attaching files to Outlook messages. This vulner An information disclosure vulnerability exists when attaching files to Outlook messages. This vulnerability could potentially allow users to share attached files such that they are accessible by anonymous users where they should be restricted to specific users. To exploit this vulnerability, an attacker would have to attach a file as a link to an emai
nvd
CVE-2017-17689P4MEDIUMCVSS 5.9v2007v2010+2 more2018-05-16
CVE-2017-17689 [MEDIUM] CVE-2017-17689: The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can in The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
nvd
CVE-2006-2055P4MEDIUMCVSS 5.0v20032006-04-26
CVE-2006-2055 [MEDIUM] CWE-88 CVE-2006-2055: Argument injection vulnerability in Microsoft Outlook 2003 SP1 allows user-assisted remote attackers Argument injection vulnerability in Microsoft Outlook 2003 SP1 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment. NOTE: it is not clear whether this issue
nvd
CVE-2017-8572P4MEDIUMCVSS 5.5v2007v2010+2 more2017-08-01
CVE-2017-8572 [MEDIUM] CWE-200 CVE-2017-8572: Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 201 Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 2016 as packaged in Microsoft Office allows an information disclosure vulnerability due to the way that it discloses the contents of its memory, aka "Microsoft Office Outlook Information Disclosure Vulnerability".
nvd
CVE-2001-0145P4HIGHCVSS 7.5v98v20002001-05-03
CVE-2001-0145 [HIGH] CVE-2001-0145: Buffer overflow in VCard handler in Outlook 2000 and 98, and Outlook Express 5.x, allows an attacker Buffer overflow in VCard handler in Outlook 2000 and 98, and Outlook Express 5.x, allows an attacker to execute arbitrary commands via a malformed vCard birthday field.
nvd
CVE-2004-2482P4MEDIUMCVSS 5.0v2000v20032004-12-31
CVE-2004-2482 [MEDIUM] CVE-2004-2482: Microsoft Outlook 2000 and 2003, when configured to use Microsoft Word 2000 or 2003 as the e-mail ed Microsoft Outlook 2000 and 2003, when configured to use Microsoft Word 2000 or 2003 as the e-mail editor and when forwarding e-mail, does not properly handle an opening OBJECT tag that does not have a closing OBJECT tag, which causes Outlook to automatically download the URI in the data property of the OBJECT tag and might allow remote attackers to execute ar
nvd
CVE-2019-0560P4MEDIUMCVSS 5.5v2010-sp2v2013-sp1+1 more2019-01-08
CVE-2019-0560 [MEDIUM] CVE-2019-0560: An information disclosure vulnerability exists when Microsoft Office improperly discloses the conten An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, aka "Microsoft Office Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office.
nvd
CVE-2017-8508P4MEDIUMCVSS 5.5v2007v2010+2 more2017-06-15
CVE-2017-8508 [MEDIUM] CVE-2017-8508: A security feature bypass vulnerability exists in Microsoft Office software when it improperly handl A security feature bypass vulnerability exists in Microsoft Office software when it improperly handles the parsing of file formats, aka "Microsoft Office Security Feature Bypass Vulnerability".
nvd
CVE-2006-1305P4MEDIUMCVSS 4.3v2000v2002+1 more2006-12-31
CVE-2006-1305 [MEDIUM] CWE-399 CVE-2006-1305: Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to cause a denial of se Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to cause a denial of service (memory exhaustion and interrupted mail recovery) via malformed e-mail header information, possibly related to (1) long subject lines or (2) large numbers of recipients in To or CC headers.
nvd
CVE-2026-62882P4MEDIUMCVSS 4.3v20162026-08-11
CVE-2026-62882 [MEDIUM] CWE-522 CVE-2026-62882: Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2019-1204P4MEDIUMCVSS 4.3v2010v2013+1 more2019-08-14
CVE-2019-1204 [MEDIUM] CWE-20 CVE-2019-1204: An elevation of privilege vulnerability exists when Microsoft Outlook initiates processing of incomi An elevation of privilege vulnerability exists when Microsoft Outlook initiates processing of incoming messages without sufficient validation of the formatting of the messages. An attacker who successfully exploited the vulnerability could attempt to force Outlook to load a local or remote message store (over SMB). To exploit the vulnerability, the att
nvd
CVE-2004-0503P4MEDIUMCVSS 5.0v20032004-08-18
CVE-2004-0503 [MEDIUM] CVE-2004-0503: Microsoft Outlook 2003 allows remote attackers to bypass the default zone restrictions and execute s Microsoft Outlook 2003 allows remote attackers to bypass the default zone restrictions and execute script within media files via a Rich Text Format (RTF) message containing an OLE object for the Windows Media Player, which bypasses Media Player's setting to disallow scripting and may lead to unprompted installation of an executable when exploited in conjuncti
nvd
CVE-2005-1052P4MEDIUMCVSS 5.0v20032005-05-02
CVE-2005-1052 [MEDIUM] CVE-2005-1052: Microsoft Outlook 2003 and Outlook Web Access (OWA) 2003 do not properly display comma separated add Microsoft Outlook 2003 and Outlook Web Access (OWA) 2003 do not properly display comma separated addresses in the From field in an e-mail message, which could allow remote attackers to spoof e-mail addresses.
nvd
Microsoft Outlook vulnerabilities | cvebase