Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Filtered by product Outlook
Total 114 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-0145 1 Microsoft 2 Outlook, Outlook Express 2025-04-03 7.5 HIGH N/A
Buffer overflow in VCard handler in Outlook 2000 and 98, and Outlook Express 5.x, allows an attacker to execute arbitrary commands via a malformed vCard birthday field.
CVE-2004-2482 1 Microsoft 1 Outlook 2025-04-03 5.0 MEDIUM N/A
Microsoft Outlook 2000 and 2003, when configured to use Microsoft Word 2000 or 2003 as the e-mail editor and when forwarding e-mail, does not properly handle an opening OBJECT tag that does not have a closing OBJECT tag, which causes Outlook to automatically download the URI in the data property of the OBJECT tag and might allow remote attackers to execute arbitrary code.
CVE-2000-0160 1 Microsoft 3 Ie, Internet Explorer, Outlook 2025-04-03 7.6 HIGH N/A
The Microsoft Active Setup ActiveX component in Internet Explorer 4.x and 5.x allows a remote attacker to install software components without prompting the user by stating that the software's manufacturer is Microsoft.
CVE-2001-0322 1 Microsoft 3 Internet Explorer, Outlook, Outlook Express 2025-04-03 5.0 MEDIUM N/A
MSHTML.DLL HTML parser in Internet Explorer 4.0, and other versions, allows remote attackers to cause a denial of service (application crash) via a script that creates and deletes an object that is associated with the browser window object.
CVE-2004-0501 1 Microsoft 1 Outlook 2025-04-03 5.0 MEDIUM N/A
Outlook 2003 allows remote attackers to bypass intended access restrictions and cause Outlook to request a URL from a remote site via an HTML e-mail message containing a Vector Markup Language (VML) entity whose src parameter points to the remote site, which could allow remote attackers to know when a message has been read, verify valid e-mail addresses, and possibly leak other information.
CVE-2003-0007 1 Microsoft 1 Outlook 2025-04-03 5.0 MEDIUM N/A
Microsoft Outlook 2002 does not properly handle requests to encrypt email messages with V1 Exchange Server Security certificates, which causes Outlook to send the email in plaintext, aka "Flaw in how Outlook 2002 handles V1 Exchange Server Security Certificates could lead to Information Disclosure."
CVE-1999-1164 1 Microsoft 2 Outlook, Outlook Express 2025-04-03 5.0 MEDIUM N/A
Microsoft Outlook client allows remote attackers to cause a denial of service by sending multiple email messages with the same X-UIDL headers, which causes Outlook to hang.
CVE-2006-4868 1 Microsoft 5 Internet Explorer, Outlook, Windows 2000 and 2 more 2025-04-03 9.3 HIGH N/A
Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft Outlook and Internet Explorer 6.0 on Windows XP SP2, and possibly other versions, allows remote attackers to execute arbitrary code via a Vector Markup Language (VML) file with a long fill parameter within a rect tag.
CVE-2023-23397 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2025-03-13 N/A 9.8 CRITICAL
Microsoft Outlook Elevation of Privilege Vulnerability
CVE-2023-33131 1 Microsoft 4 Office, Office Long Term Servicing Channel, Outlook and 1 more 2025-02-28 N/A 8.8 HIGH
Microsoft Outlook Remote Code Execution Vulnerability
CVE-2021-31949 1 Microsoft 3 365 Apps, Office, Outlook 2025-02-28 6.8 MEDIUM 7.3 HIGH
Microsoft Outlook Remote Code Execution Vulnerability
CVE-2025-21259 1 Microsoft 1 Outlook 2025-02-28 N/A 5.3 MEDIUM
Microsoft Outlook Spoofing Vulnerability
CVE-2023-35311 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2025-02-24 N/A 8.8 HIGH
Microsoft Outlook Security Feature Bypass Vulnerability
CVE-2025-21361 1 Microsoft 2 Office, Outlook 2025-01-17 N/A 7.8 HIGH
Microsoft Outlook Remote Code Execution Vulnerability
CVE-2024-26204 1 Microsoft 1 Outlook 2025-01-15 N/A 7.5 HIGH
Outlook for Android Information Disclosure Vulnerability
CVE-2024-20670 1 Microsoft 2 Outlook, Windows 2025-01-08 N/A 8.1 HIGH
Outlook for Windows Spoofing Vulnerability
CVE-2022-24480 1 Microsoft 1 Outlook 2025-01-02 N/A 6.3 MEDIUM
Outlook for Android Elevation of Privilege Vulnerability
CVE-2024-38020 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2024-11-21 N/A 6.5 MEDIUM
Microsoft Outlook Spoofing Vulnerability
CVE-2024-30103 1 Microsoft 3 365 Apps, Office, Outlook 2024-11-21 N/A 8.8 HIGH
Microsoft Outlook Remote Code Execution Vulnerability
CVE-2024-21378 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2024-11-21 N/A 8.8 HIGH
Microsoft Outlook Remote Code Execution Vulnerability