VendorsMicrosoftoutlook2016
Vulnerabilities

Microsoft Outlook 2016

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

58CVEs
CVE-2016-3366
Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, Outlook 2016, and Outlook 2016 for Mac do not properly implement RFC 2046, which allows remote attackers to bypass virus or spam detection via crafted MIME data in an e-mail attachment, aka "Microsoft Office Spoofing Vulnerability."
Published 2016-09-14 · Modified
6.5EPSS 0.162
CVE-2019-0559
An information disclosure vulnerability exists when Microsoft Outlook improperly handles certain types of messages, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook.
Published 2019-01-08 · Modified
6.5EPSS 0.068
CVE-2019-1084
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by validating display names upon creation in Microsoft Exchange, and by rendering invalid display names correctly in Microsoft Outlook clients., aka 'Microsoft Exchange Information Disclosure Vulnerability'.
Published 2019-07-15 · Modified
6.5EPSS 0.053
CVE-2018-8244
An elevation of privilege vulnerability exists when Microsoft Outlook does not validate attachment headers properly, aka "Microsoft Outlook Elevation of Privilege Vulnerability." This affects Microsoft Office, Microsoft Outlook.
Published 2018-06-14 · Modified
6.5EPSS 0.053
CVE-2018-0850
Microsoft Outlook 2007, Microsoft Outlook 2010, Microsoft Outlook 2013, Microsoft Outlook 2016, and Microsoft Office 2016 Click-to-Run allow an elevation of privilege vulnerability due to how the format of incoming message is validated, aka "Microsoft Outlook Elevation of Privilege Vulnerability".
Published 2018-02-15 · Modified
6.5EPSS 0.050
CVE-2020-0696
A security feature bypass vulnerability exists in Microsoft Outlook software when it improperly handles the parsing of URI formats, aka 'Microsoft Outlook Security Feature Bypass Vulnerability'.
Published 2020-02-11 · Modified
6.5EPSS 0.050
CVE-2017-8545
A spoofing vulnerability exists in when Microsoft Outlook for Mac does not sanitize html properly, aka "Microsoft Outlook for Mac Spoofing Vulnerability".
Published 2017-06-15 · Modified
6.5EPSS 0.050
CVE-2023-36893
Microsoft Outlook Spoofing Vulnerability
Published 2023-08-08 · Modified
6.5EPSS 0.022
CVE-2024-38020
Microsoft Outlook Spoofing Vulnerability
Published 2024-07-09 · Modified
6.5EPSS 0.018
CVE-2026-80073
Microsoft Office Outlook Information Disclosure Vulnerability
Published 2026-09-08 · Analyzed
6.5EPSS 0.009
CVE-2017-17689
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
Published 2018-05-16 · Modified
5.9EPSS 0.041
CVE-2017-0204
Microsoft Outlook 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1, and Microsoft Outlook 2016 allow remote attackers to bypass the Office Protected View via a specially crafted document, aka "Microsoft Office Security Feature Bypass Vulnerability."
Published 2017-04-12 · Modified
5.5EPSS 0.190
CVE-2017-8572
Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 2016 as packaged in Microsoft Office allows an information disclosure vulnerability due to the way that it discloses the contents of its memory, aka "Microsoft Office Outlook Information Disclosure Vulnerability".
Published 2017-08-01 · Modified
5.5EPSS 0.126
CVE-2019-0560
An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, aka "Microsoft Office Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office.
Published 2019-01-08 · Modified
5.5EPSS 0.087
CVE-2020-1493
Microsoft Outlook Information Disclosure Vulnerability
Published 2020-08-17 · Modified
5.5EPSS 0.073
CVE-2017-8508
A security feature bypass vulnerability exists in Microsoft Office software when it improperly handles the parsing of file formats, aka "Microsoft Office Security Feature Bypass Vulnerability".
Published 2017-06-15 · Modified
5.5EPSS 0.042
CVE-2019-1204
Microsoft Outlook Elevation of Privilege Vulnerability
Published 2019-08-14 · Modified
4.3EPSS 0.044
CVE-2026-62882
Microsoft Outlook Spoofing Vulnerability
Published 2026-08-11 · Analyzed
4.3EPSS 0.007
← Prev2 / 2