VendorsMicrosoftoutlookall versions
Vulnerabilities

Microsoft Outlook

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

126CVEs
CVE-2003-0007
Microsoft Outlook 2002 does not properly handle requests to encrypt email messages with V1 Exchange Server Security certificates, which causes Outlook to send the email in plaintext, aka "Flaw in how Outlook 2002 handles V1 Exchange Server Security Certificates could lead to Information Disclosure."
Published 2004-09-01 · Modified
5.0EPSS 0.039
CVE-2019-1460
A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages, aka 'Outlook for Android Spoofing Vulnerability'.
Published 2020-01-24 · Modified
4.6EPSS 0.014
CVE-1999-0384
The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content.
Published 1999-09-29 · Modified
4.6EPSS 0.012
CVE-2006-1305
Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to cause a denial of service (memory exhaustion and interrupted mail recovery) via malformed e-mail header information, possibly related to (1) long subject lines or (2) large numbers of recipients in To or CC headers.
Published 2007-01-09 · Modified
4.3EPSS 0.317
CVE-2019-1204
Microsoft Outlook Elevation of Privilege Vulnerability
Published 2019-08-14 · Modified
4.3EPSS 0.044
CVE-2026-62882
Microsoft Outlook Spoofing Vulnerability
Published 2026-08-11 · Analyzed
4.3EPSS 0.007
← Prev4 / 4