cbcvebase.

Microsoft Outlook vulnerabilities

111 known vulnerabilities affecting microsoft/outlook.

Total CVEs
111
CISA KEV
5
actively exploited
Public exploits
18
Exploited in wild
6
Severity breakdown
CRITICAL11HIGH55MEDIUM45

Vulnerabilities

Page 6 of 6
CVE-2002-0481P4MEDIUMCVSS 5.1v20022002-08-12
CVE-2002-0481 [MEDIUM] CVE-2002-0481: An interaction between Windows Media Player (WMP) and Outlook 2002 allows remote attackers to bypass An interaction between Windows Media Player (WMP) and Outlook 2002 allows remote attackers to bypass Outlook security settings and execute Javascript via an IFRAME in an HTML email message that references .WMS (Windows Media Skin) or other WMP media files, whose onload handlers execute the player.LaunchURL() Javascript function.
nvd
CVE-1999-1164P4MEDIUMCVSS 5.0v97v98+1 more1999-06-25
CVE-1999-1164 [MEDIUM] CVE-1999-1164: Microsoft Outlook client allows remote attackers to cause a denial of service by sending multiple em Microsoft Outlook client allows remote attackers to cause a denial of service by sending multiple email messages with the same X-UIDL headers, which causes Outlook to hang.
nvd
CVE-2002-2100P4MEDIUMCVSS 5.0v2000v20022002-12-31
CVE-2002-2100 [MEDIUM] CVE-2002-2100: Microsoft Outlook 2002 allows remote attackers to embed bypass the file download restrictions for at Microsoft Outlook 2002 allows remote attackers to embed bypass the file download restrictions for attachments via an HTML email message that uses an IFRAME to reference malicious content.
nvd
CVE-2004-0284P4MEDIUMCVSS 5.0v2002v20032004-11-23
CVE-2004-0284 [MEDIUM] CVE-2004-0284: Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a de Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%00) after the host name.
nvd
CVE-2002-1255P4MEDIUMCVSS 5.0v20022002-12-18
CVE-2002-1255 [MEDIUM] CVE-2002-1255: Microsoft Outlook 2002 allows remote attackers to cause a denial of service (repeated failure) via a Microsoft Outlook 2002 allows remote attackers to cause a denial of service (repeated failure) via an email message with a certain invalid header field that is accessed using POP3, IMAP, or WebDAV, aka "E-mail Header Processing Flaw Could Cause Outlook 2002 to Fail."
nvd
CVE-2003-0007P4MEDIUMCVSS 5.0v20022003-02-07
CVE-2003-0007 [MEDIUM] CVE-2003-0007: Microsoft Outlook 2002 does not properly handle requests to encrypt email messages with V1 Exchange Microsoft Outlook 2002 does not properly handle requests to encrypt email messages with V1 Exchange Server Security certificates, which causes Outlook to send the email in plaintext, aka "Flaw in how Outlook 2002 handles V1 Exchange Server Security Certificates could lead to Information Disclosure."
nvd
CVE-2000-0415P4MEDIUMCVSS 5.0v982000-05-12
CVE-2000-0415 [MEDIUM] CVE-2000-0415: Buffer overflow in Outlook Express 4.x allows attackers to cause a denial of service via a mail or n Buffer overflow in Outlook Express 4.x allows attackers to cause a denial of service via a mail or news message that has a .jpg or .bmp attachment with a long file name.
nvd
CVE-2000-0524P4MEDIUMCVSS 5.0v972000-06-05
CVE-2000-0524 [MEDIUM] CVE-2000-0524: Microsoft Outlook and Outlook Express allow remote attackers to cause a denial of service by sending Microsoft Outlook and Outlook Express allow remote attackers to cause a denial of service by sending email messages with blank fields such as BCC, Reply-To, Return-Path, or From.
nvd
CVE-2000-0753P4MEDIUMCVSS 5.0v97v98+1 more2000-10-20
CVE-2000-0753 [MEDIUM] CVE-2000-0753: The Microsoft Outlook mail client identifies the physical path of the sender's machine within a winm The Microsoft Outlook mail client identifies the physical path of the sender's machine within a winmail.dat attachment to Rich Text Format (RTF) files.
nvd
CVE-2000-0756P4MEDIUMCVSS 5.0v98v20002000-10-20
CVE-2000-0756 [MEDIUM] CVE-2000-0756: Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, whi Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service.
nvd
CVE-1999-0384P4MEDIUMCVSS 4.6v981999-01-01
CVE-1999-0384 [MEDIUM] CVE-1999-0384: The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content.
nvd
Microsoft Outlook vulnerabilities | cvebase