cbcvebase.

Microsoft Outlook Express vulnerabilities

41 known vulnerabilities affecting microsoft/outlook_express.

Total CVEs
41
CISA KEV
0
Public exploits
18
Exploited in wild
1
Severity breakdown
CRITICAL4HIGH12MEDIUM24LOW1

Vulnerabilities

Page 2 of 3
CVE-2001-0322P4MEDIUMCVSS 5.0PoCv5.52001-06-02
CVE-2001-0322 [MEDIUM] CVE-2001-0322: MSHTML.DLL HTML parser in Internet Explorer 4.0, and other versions, allows remote attackers to caus MSHTML.DLL HTML parser in Internet Explorer 4.0, and other versions, allows remote attackers to cause a denial of service (application crash) via a script that creates and deletes an object that is associated with the browser window object.
nvd
CVE-2001-1547P3HIGHCVSS 7.5v6.02001-12-31
CVE-2001-1547 [HIGH] CVE-2001-1547: Outlook Express 6.0, with "Do not allow attachments to be saved or opened that could potentially be Outlook Express 6.0, with "Do not allow attachments to be saved or opened that could potentially be a virus" enabled, does not block email attachments from forwarded messages, which could allow remote attackers to execute arbitrary code.
nvd
CVE-1999-1016P4MEDIUMCVSS 5.0PoCv5.01999-08-27
CVE-1999-1016 [MEDIUM] CVE-1999-1016: Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Expr Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as text inputs in a table cell.
nvd
CVE-2001-0999P4HIGHCVSS 7.5v6.02001-09-12
CVE-2001-0999 [HIGH] CVE-2001-0999: Outlook Express 6.00 allows remote attackers to execute arbitrary script by embedding SCRIPT tags in Outlook Express 6.00 allows remote attackers to execute arbitrary script by embedding SCRIPT tags in a message whose MIME content type is text/plain, contrary to the expected behavior that text/plain messages will not run script.
nvd
CVE-2002-0152P4HIGHCVSS 7.5v5.0v5.0.1+2 more2002-04-22
CVE-2002-0152 [HIGH] CVE-2002-0152: Buffer overflow in various Microsoft applications for Macintosh allows remote attackers to cause a d Buffer overflow in various Microsoft applications for Macintosh allows remote attackers to cause a denial of service (crash) or execute arbitrary code by invoking the file:// directive with a large number of / characters, which affects Internet Explorer 5.1, Outlook Express 5.0 through 5.0.2, Entourage v. X and 2001, PowerPoint v. X, 2001, and 98, and Excel v.
nvd
CVE-2000-0621P4HIGHCVSS 7.5v4.0v4.01+2 more2000-07-20
CVE-2000-0621 [HIGH] CVE-2000-0621: Microsoft Outlook 98 and 2000, and Outlook Express 4.0x and 5.0x, allow remote attackers to read fil Microsoft Outlook 98 and 2000, and Outlook Express 4.0x and 5.0x, allow remote attackers to read files on the client's system via a malformed HTML message that stores files outside of the cache, aka the "Cache Bypass" vulnerability.
nvd
CVE-2002-0285P4HIGHCVSS 7.5v5.5v6.02002-05-31
CVE-2002-0285 [HIGH] CVE-2002-0285: Outlook Express 5.5 and 6.0 on Windows treats a carriage return ("CR") in a message header as if it Outlook Express 5.5 and 6.0 on Windows treats a carriage return ("CR") in a message header as if it were a valid carriage return/line feed combination (CR/LF), which could allow remote attackers to bypass virus protection and or other filtering mechanisms via a mail message with headers that only contain the CR, which causes Outlook to create separate headers.
nvd
CVE-2001-0145P4HIGHCVSS 7.5v5.02001-05-03
CVE-2001-0145 [HIGH] CVE-2001-0145: Buffer overflow in VCard handler in Outlook 2000 and 98, and Outlook Express 5.x, allows an attacker Buffer overflow in VCard handler in Outlook 2000 and 98, and Outlook Express 5.x, allows an attacker to execute arbitrary commands via a malformed vCard birthday field.
nvd
CVE-2007-2225P4MEDIUMCVSS 4.3v6.02007-06-12
CVE-2007-2225 [MEDIUM] CVE-2007-2225: A component in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handl A component in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handle certain HTTP headers when processing MHTML protocol URLs, which allows remote attackers to obtain sensitive information from other Internet Explorer domains, aka "URL Parsing Cross Domain Information Disclosure Vulnerability."
nvd
CVE-2004-2694P4MEDIUMCVSS 5.8v6.02004-12-31
CVE-2004-2694 [MEDIUM] CWE-264 CVE-2004-2694: Microsoft Outlook Express 6.0 allows remote attackers to bypass intended access restrictions, load c Microsoft Outlook Express 6.0 allows remote attackers to bypass intended access restrictions, load content from arbitrary sources into the Outlook context, and facilitate phishing attacks via a "BASE HREF" with the target set to "_top".
nvd
CVE-2004-2137P4MEDIUMCVSS 5.0v6.02004-12-31
CVE-2004-2137 [MEDIUM] CVE-2004-2137: Outlook Express 6.0, when sending multipart e-mail messages using the "Break apart messages larger t Outlook Express 6.0, when sending multipart e-mail messages using the "Break apart messages larger than" setting, leaks the BCC recipients of the message to the addresses listed in the To and CC fields, which may allow remote attackers to obtain sensitive information.
nvd
CVE-2007-2227P4MEDIUMCVSS 4.3v6.02007-06-12
CVE-2007-2227 [MEDIUM] CVE-2007-2227: The MHTML protocol handler in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not The MHTML protocol handler in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handle Content-Disposition "notifications," which allows remote attackers to obtain sensitive information from other Internet Explorer domains, aka "Content Disposition Parsing Cross Domain Information Disclosure Vulnerability."
nvd
CVE-2001-0945P4MEDIUMCVSS 5.0v5.0v5.0.1+1 more2001-12-03
CVE-2001-0945 [MEDIUM] CVE-2001-0945: Buffer overflow in Outlook Express 5.0 through 5.02 for Macintosh allows remote attackers to cause a Buffer overflow in Outlook Express 5.0 through 5.02 for Macintosh allows remote attackers to cause a denial of service via an e-mail message that contains a long line.
nvd
CVE-2005-2226P4MEDIUMCVSS 5.0v6.02005-07-12
CVE-2005-2226 [MEDIUM] CVE-2005-2226: Microsoft Outlook Express 6.0 leaks the default news server account when a user responds to a "watch Microsoft Outlook Express 6.0 leaks the default news server account when a user responds to a "watched" conversation thread, which could allow remote attackers to obtain sensitive information.
nvd
CVE-2008-5424P4MEDIUMCVSS 4.3v6.00.2900.55122008-12-11
CVE-2008-5424 [MEDIUM] CVE-2008-5424: The MimeOleClearDirtyTree function in InetComm.dll in Microsoft Outlook Express 6.00.2900.5512 does The MimeOleClearDirtyTree function in InetComm.dll in Microsoft Outlook Express 6.00.2900.5512 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822;" headers, which allows remote attackers to cause a denial of service (infinite loop) via a large e-mail message
nvd
CVE-2000-0415P4MEDIUMCVSS 5.0v4.0v4.01+4 more2000-05-12
CVE-2000-0415 [MEDIUM] CVE-2000-0415: Buffer overflow in Outlook Express 4.x allows attackers to cause a denial of service via a mail or n Buffer overflow in Outlook Express 4.x allows attackers to cause a denial of service via a mail or news message that has a .jpg or .bmp attachment with a long file name.
nvd
CVE-2003-0301P4MEDIUMCVSS 5.0v6.00.2800.11062003-06-16
CVE-2003-0301 [MEDIUM] CVE-2003-0301: The IMAP Client for Outlook Express 6.00.2800.1106 allows remote malicious IMAP servers to cause a d The IMAP Client for Outlook Express 6.00.2800.1106 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors.
nvd
CVE-2004-0215P4MEDIUMCVSS 5.0v6.02004-08-06
CVE-2004-0215 [MEDIUM] CVE-2004-0215: Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header.
nvd
CVE-2003-0300P4MEDIUMCVSS 5.0v6.00.2800.11062003-06-16
CVE-2003-0300 [MEDIUM] CVE-2003-0300: The IMAP Client for Sylpheed 0.8.11 allows remote malicious IMAP servers to cause a denial of servic The IMAP Client for Sylpheed 0.8.11 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors.
nvd
CVE-2000-0036P4MEDIUMCVSS 5.0v5.01999-12-22
CVE-2000-0036 [MEDIUM] CVE-2000-0036: Outlook Express 5 for Macintosh downloads attachments to HTML mail without prompting the user, aka t Outlook Express 5 for Macintosh downloads attachments to HTML mail without prompting the user, aka the "HTML Mail Attachment" vulnerability.
nvd
Microsoft Outlook Express vulnerabilities | cvebase