VendorsMicrosoftoutlookall versions
Vulnerabilities

Microsoft Outlook

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

126CVEs
CVE-2020-0696
A security feature bypass vulnerability exists in Microsoft Outlook software when it improperly handles the parsing of URI formats, aka 'Microsoft Outlook Security Feature Bypass Vulnerability'.
Published 2020-02-11 · Modified
6.5EPSS 0.050
CVE-2017-8545
A spoofing vulnerability exists in when Microsoft Outlook for Mac does not sanitize html properly, aka "Microsoft Outlook for Mac Spoofing Vulnerability".
Published 2017-06-15 · Modified
6.5EPSS 0.050
CVE-2023-36893
Microsoft Outlook Spoofing Vulnerability
Published 2023-08-08 · Modified
6.5EPSS 0.022
CVE-2024-38020
Microsoft Outlook Spoofing Vulnerability
Published 2024-07-09 · Modified
6.5EPSS 0.018
CVE-2024-43482
Microsoft Outlook for iOS Information Disclosure Vulnerability
Published 2024-09-10 · Analyzed
6.5EPSS 0.011
CVE-2026-80073
Microsoft Office Outlook Information Disclosure Vulnerability
Published 2026-09-08 · Analyzed
6.5EPSS 0.009
CVE-2022-24480
Outlook for Android Elevation of Privilege Vulnerability
Published 2022-12-13 · Modified
6.3EPSS 0.006
CVE-2017-17688
The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an obsolete packet type, not a problem in the OpenPGP specification
Published 2018-05-16 · Modified
5.9EPSS 0.055
CVE-2017-17689
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
Published 2018-05-16 · Modified
5.9EPSS 0.041
CVE-2017-0204
Microsoft Outlook 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1, and Microsoft Outlook 2016 allow remote attackers to bypass the Office Protected View via a specially crafted document, aka "Microsoft Office Security Feature Bypass Vulnerability."
Published 2017-04-12 · Modified
5.5EPSS 0.190
CVE-2017-8572
Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 2016 as packaged in Microsoft Office allows an information disclosure vulnerability due to the way that it discloses the contents of its memory, aka "Microsoft Office Outlook Information Disclosure Vulnerability".
Published 2017-08-01 · Modified
5.5EPSS 0.126
CVE-2019-0560
An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, aka "Microsoft Office Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office.
Published 2019-01-08 · Modified
5.5EPSS 0.087
CVE-2020-1493
Microsoft Outlook Information Disclosure Vulnerability
Published 2020-08-17 · Modified
5.5EPSS 0.073
CVE-2017-8508
A security feature bypass vulnerability exists in Microsoft Office software when it improperly handles the parsing of file formats, aka "Microsoft Office Security Feature Bypass Vulnerability".
Published 2017-06-15 · Modified
5.5EPSS 0.042
CVE-2002-1696
Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a message to hard disk when "Automatically decrypt/verify when opening messages" option is checked, "Always use Secure Viewer when decrypting" option is not checked, and the user replies to an encrypted message.
Published 2005-06-21 · Modified
5.5EPSS 0.003
CVE-2019-1218
Outlook iOS Spoofing Vulnerability
Published 2019-08-14 · Modified
5.4EPSS 0.039
CVE-2019-1105
Outlook for Android Spoofing Vulnerability
Published 2019-07-29 · Modified
5.4EPSS 0.018
CVE-2025-21259
Microsoft Outlook Spoofing Vulnerability
Published 2025-02-11 · Analyzed
5.3EPSS 0.012
CVE-2002-0481
An interaction between Windows Media Player (WMP) and Outlook 2002 allows remote attackers to bypass Outlook security settings and execute Javascript via an IFRAME in an HTML email message that references .WMS (Windows Media Skin) or other WMP media files, whose onload handlers execute the player.LaunchURL() Javascript function.
Published 2002-06-11 · Modified
5.1EPSS 0.101
CVE-2000-0329
A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an attachment and an embedded script in an HTML mail, aka the "Active Setup Control" vulnerability.
Published 2000-06-02 · Modified
5.11 PoCEPSS 0.077
CVE-2000-0567
Buffer overflow in Microsoft Outlook and Outlook Express allows remote attackers to execute arbitrary commands via a long Date field in an email header, aka the "Malformed E-mail Header" vulnerability.
Published 2000-10-13 · Modified
5.02 PoCEPSS 0.323
CVE-2001-0322
MSHTML.DLL HTML parser in Internet Explorer 4.0, and other versions, allows remote attackers to cause a denial of service (application crash) via a script that creates and deletes an object that is associated with the browser window object.
Published 2001-04-04 · Modified
5.01 PoCEPSS 0.210
CVE-2004-0502
Outlook 2003, when replying to an e-mail message, stores certain files in a predictable location for the "src" of an img tag of the original message, which allows remote attackers to bypass zone restrictions and exploit other issues that rely on predictable locations, as demonstrated using a shell: URI.
Published 2004-06-03 · Modified
5.01 PoCEPSS 0.202
CVE-2004-0501
Outlook 2003 allows remote attackers to bypass intended access restrictions and cause Outlook to request a URL from a remote site via an HTML e-mail message containing a Vector Markup Language (VML) entity whose src parameter points to the remote site, which could allow remote attackers to know when a message has been read, verify valid e-mail addresses, and possibly leak other information.
Published 2004-06-03 · Modified
5.01 PoCEPSS 0.187
CVE-2006-6659
The Microsoft Office Outlook Recipient ActiveX control (ole32.dll) in Windows XP SP2 allows remote attackers to cause a denial of service (Internet Explorer 7 hang) via crafted HTML.
Published 2006-12-20 · Modified
5.02 PoCEPSS 0.176
CVE-2004-0526
Unknown versions of Internet Explorer and Outlook allow remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.
Published 2004-06-08 · Modified
5.01 PoCEPSS 0.172
CVE-2004-0284
Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%00) after the host name.
Published 2004-03-18 · Modified
5.0EPSS 0.168
CVE-2006-2055
Argument injection vulnerability in Microsoft Outlook 2003 SP1 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment. NOTE: it is not clear whether this issue is implementation-specific or a problem in the Microsoft API.
Published 2006-04-26 · Modified
5.0EPSS 0.154
CVE-2000-0524
Microsoft Outlook and Outlook Express allow remote attackers to cause a denial of service by sending email messages with blank fields such as BCC, Reply-To, Return-Path, or From.
Published 2000-07-12 · Modified
5.0EPSS 0.146
CVE-2002-1255
Microsoft Outlook 2002 allows remote attackers to cause a denial of service (repeated failure) via an email message with a certain invalid header field that is accessed using POP3, IMAP, or WebDAV, aka "E-mail Header Processing Flaw Could Cause Outlook 2002 to Fail."
Published 2004-09-01 · Modified
5.0EPSS 0.140
CVE-1999-1164
Microsoft Outlook client allows remote attackers to cause a denial of service by sending multiple email messages with the same X-UIDL headers, which causes Outlook to hang.
Published 2001-09-12 · Modified
5.0EPSS 0.132
CVE-2004-2482
Microsoft Outlook 2000 and 2003, when configured to use Microsoft Word 2000 or 2003 as the e-mail editor and when forwarding e-mail, does not properly handle an opening OBJECT tag that does not have a closing OBJECT tag, which causes Outlook to automatically download the URI in the data property of the OBJECT tag and might allow remote attackers to execute arbitrary code.
Published 2005-08-21 · Modified
5.0EPSS 0.128
CVE-2013-3905
Microsoft Outlook 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT does not properly expand metadata contained in S/MIME certificates, which allows remote attackers to obtain sensitive network configuration and state information via a crafted certificate in an e-mail message, aka "S/MIME AIA Vulnerability."
Published 2013-11-13 · Modified
5.0EPSS 0.119
CVE-2004-0503
Microsoft Outlook 2003 allows remote attackers to bypass the default zone restrictions and execute script within media files via a Rich Text Format (RTF) message containing an OLE object for the Windows Media Player, which bypasses Media Player's setting to disallow scripting and may lead to unprompted installation of an executable when exploited in conjunction with predictable-file-location exposures such as CVE-2004-0502.
Published 2004-06-03 · Modified
5.0EPSS 0.114
CVE-2002-2100
Microsoft Outlook 2002 allows remote attackers to embed bypass the file download restrictions for attachments via an HTML email message that uses an IFRAME to reference malicious content.
Published 2005-08-05 · Modified
5.0EPSS 0.114
CVE-2005-1052
Microsoft Outlook 2003 and Outlook Web Access (OWA) 2003 do not properly display comma separated addresses in the From field in an e-mail message, which could allow remote attackers to spoof e-mail addresses.
Published 2005-04-12 · Modified
5.0EPSS 0.094
CVE-2000-0415
Buffer overflow in Outlook Express 4.x allows attackers to cause a denial of service via a mail or news message that has a .jpg or .bmp attachment with a long file name.
Published 2000-06-15 · Modified
5.0EPSS 0.060
CVE-2000-0753
The Microsoft Outlook mail client identifies the physical path of the sender's machine within a winmail.dat attachment to Rich Text Format (RTF) files.
Published 2002-03-09 · Modified
5.0EPSS 0.052
CVE-2000-0756
Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service.
Published 2000-09-21 · Modified
5.0EPSS 0.051
CVE-2000-0216
Microsoft email clients in Outlook, Exchange, and Windows Messaging automatically respond to Read Receipt and Delivery Receipt tags, which could allow an attacker to flood a mail system with responses by forging a Read Receipt request that is redirected to a large distribution list.
Published 2000-03-22 · Modified
5.0EPSS 0.051
← Prev3 / 4Next →