VendorsMicrosoftoutlookall versions
Vulnerabilities

Microsoft Outlook

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

126CVEs
CVE-2024-43604
Outlook for Android Elevation of Privilege Vulnerability
Published 2024-10-08 · Analyzed
8.0EPSS 0.012
CVE-2017-11774
Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Office handles objects in memory, aka "Microsoft Outlook Security Feature Bypass Vulnerability."
Published 2017-10-13 · Analyzed
7.8KEVEPSS 0.596
CVE-2020-1349
A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka 'Microsoft Outlook Remote Code Execution Vulnerability'.
Published 2020-07-14 · Modified
7.8EPSS 0.224
CVE-2017-8571
Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 2016 as packaged in Microsoft Office allows a security feature bypass vulnerability due to the way that it handles input, aka "Microsoft Office Outlook Security Feature Bypass Vulnerability".
Published 2017-08-01 · Modified
7.8EPSS 0.058
CVE-2021-31941
Microsoft Office Graphics Remote Code Execution Vulnerability
Published 2021-06-08 · Modified
7.8EPSS 0.029
CVE-2021-31949
Microsoft Outlook Remote Code Execution Vulnerability
Published 2021-06-08 · Modified
7.8EPSS 0.026
CVE-2021-28452
Microsoft Outlook Memory Corruption Vulnerability
Published 2021-04-13 · Modified
7.8EPSS 0.013
CVE-2025-21361
Microsoft Outlook Remote Code Execution Vulnerability
Published 2025-01-14 · Analyzed
7.8EPSS 0.007
CVE-2000-0160
The Microsoft Active Setup ActiveX component in Internet Explorer 4.x and 5.x allows a remote attacker to install software components without prompting the user by stating that the software's manufacturer is Microsoft.
Published 2000-02-23 · Modified
7.6EPSS 0.092
CVE-2004-0204
Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete arbitrary files via ".." sequences in the dynamicimag argument to crystalimagehandler.aspx.
Published 2004-06-11 · Modified
7.51 PoCEPSS 0.724
CVE-2004-0121
Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.
Published 2004-09-01 · Modified
7.51 PoCEPSS 0.477
CVE-2006-0002
Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.
Published 2006-01-10 · Modified
7.5EPSS 0.456
CVE-2022-35742
Microsoft Outlook Denial of Service Vulnerability
Published 2023-06-01 · Modified
7.5EPSS 0.223
CVE-2000-0621
Microsoft Outlook 98 and 2000, and Outlook Express 4.0x and 5.0x, allow remote attackers to read files on the client's system via a malformed HTML message that stores files outside of the cache, aka the "Cache Bypass" vulnerability.
Published 2000-10-13 · Modified
7.5EPSS 0.221
CVE-2000-0419
The Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers to conduct unauthorized activities via the "Show Me" function in Office Help, aka the "Office 2000 UA Control" vulnerability.
Published 2000-07-12 · Modified
7.5EPSS 0.214
CVE-2001-1088
Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the "Automatically put people I reply to in my address book" option enabled, do not notify the user when the "Reply-To" address is different than the "From" address, which could allow an untrusted remote attacker to spoof legitimate addresses and intercept email from the client that is intended for another user.
Published 2002-06-25 · Modified
7.51 PoCEPSS 0.197
CVE-2002-1056
Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to.
Published 2002-06-25 · Modified
7.5EPSS 0.185
CVE-2008-3068
Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan results, via a crafted certificate with an Authority Information Access (AIA) extension.
Published 2008-07-07 · Modified
7.5EPSS 0.174
CVE-2002-2101
Microsoft Outlook 2002 allows remote attackers to execute arbitrary JavaScript code, even when scripting is disabled, via an "about:" or "javascript:" URI in the href attribute of an "a" tag.
Published 2005-08-05 · Modified
7.5EPSS 0.111
CVE-2017-11776
Microsoft Outlook 2016 allows an attacker to obtain the email content of a user, due to how Outlook 2016 discloses user email content, aka "Microsoft Outlook Information Disclosure Vulnerability."
Published 2017-10-13 · Modified
7.5EPSS 0.094
CVE-2001-0145
Buffer overflow in VCard handler in Outlook 2000 and 98, and Outlook Express 5.x, allows an attacker to execute arbitrary commands via a malformed vCard birthday field.
Published 2001-04-04 · Modified
7.5EPSS 0.067
CVE-1999-0519
A NETBIOS/SMB share password is the default, null, or missing.
Published 2000-02-04 · Modified
7.5EPSS 0.056
CVE-2020-17119
Microsoft Outlook Information Disclosure Vulnerability
Published 2020-12-09 · Modified
7.5EPSS 0.040
CVE-2020-16949
Microsoft Outlook Denial of Service Vulnerability
Published 2020-10-16 · Modified
7.5EPSS 0.030
CVE-2023-36763
Microsoft Outlook Information Disclosure Vulnerability
Published 2023-09-12 · Modified
7.5EPSS 0.021
CVE-2024-26204
Outlook for Android Information Disclosure Vulnerability
Published 2024-03-12 · Analyzed
7.5EPSS 0.021
CVE-2025-29805
Outlook for Android Information Disclosure Vulnerability
Published 2025-04-08 · Analyzed
7.5EPSS 0.015
CVE-2026-21260
Microsoft Outlook Spoofing Vulnerability
Published 2026-02-10 · Analyzed
7.5EPSS 0.015
CVE-2026-42893
Microsoft Outlook for iOS Tampering Vulnerability
Published 2026-05-12 · Analyzed
7.5EPSS 0.007
CVE-2026-26133
M365 Copilot Information Disclosure Vulnerability
Published 2026-03-13 · Modified
7.1EPSS 0.005
CVE-2025-49699
Microsoft Office Remote Code Execution Vulnerability
Published 2025-07-08 · Analyzed
7.0EPSS 0.003
CVE-2025-47171
Microsoft Outlook Remote Code Execution Vulnerability
Published 2025-06-10 · Analyzed
6.71 PoCEPSS 0.017
CVE-2024-38173
Microsoft Outlook Remote Code Execution Vulnerability
Published 2024-08-13 · Analyzed
6.7EPSS 0.007
CVE-2025-21357
Microsoft Outlook Remote Code Execution Vulnerability
Published 2025-01-14 · Analyzed
6.7EPSS 0.006
CVE-2016-3366
Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, Outlook 2016, and Outlook 2016 for Mac do not properly implement RFC 2046, which allows remote attackers to bypass virus or spam detection via crafted MIME data in an e-mail attachment, aka "Microsoft Office Spoofing Vulnerability."
Published 2016-09-14 · Modified
6.5EPSS 0.162
CVE-2017-0207
Microsoft Outlook for Mac 2011 allows remote attackers to spoof web content via a crafted email with specific HTML tags, aka "Microsoft Browser Spoofing Vulnerability."
Published 2017-04-12 · Modified
6.5EPSS 0.105
CVE-2019-0559
An information disclosure vulnerability exists when Microsoft Outlook improperly handles certain types of messages, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook.
Published 2019-01-08 · Modified
6.5EPSS 0.068
CVE-2019-1084
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by validating display names upon creation in Microsoft Exchange, and by rendering invalid display names correctly in Microsoft Outlook clients., aka 'Microsoft Exchange Information Disclosure Vulnerability'.
Published 2019-07-15 · Modified
6.5EPSS 0.053
CVE-2018-8244
An elevation of privilege vulnerability exists when Microsoft Outlook does not validate attachment headers properly, aka "Microsoft Outlook Elevation of Privilege Vulnerability." This affects Microsoft Office, Microsoft Outlook.
Published 2018-06-14 · Modified
6.5EPSS 0.053
CVE-2018-0850
Microsoft Outlook 2007, Microsoft Outlook 2010, Microsoft Outlook 2013, Microsoft Outlook 2016, and Microsoft Office 2016 Click-to-Run allow an elevation of privilege vulnerability due to how the format of incoming message is validated, aka "Microsoft Outlook Elevation of Privilege Vulnerability".
Published 2018-02-15 · Modified
6.5EPSS 0.050
← Prev2 / 4Next →