VendorsMicrosoftoutlookany version
Vulnerabilities

Microsoft Outlook any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18CVEs
CVE-2001-0538
Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page.
Published 2002-03-09 · Modified
10.02 PoCEPSS 0.529
CVE-2007-4040
Argument injection vulnerability involving Microsoft Outlook and Outlook Express, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified URI, which are inserted into the command line when invoking the handling process, a similar issue to CVE-2007-3670.
Published 2007-07-27 · Modified
8.8EPSS 0.135
CVE-2024-20670
Outlook for Windows Spoofing Vulnerability
Published 2024-04-09 · Analyzed
8.1EPSS 0.023
CVE-2025-21361
Microsoft Outlook Remote Code Execution Vulnerability
Published 2025-01-14 · Analyzed
7.8EPSS 0.007
CVE-2000-0160
The Microsoft Active Setup ActiveX component in Internet Explorer 4.x and 5.x allows a remote attacker to install software components without prompting the user by stating that the software's manufacturer is Microsoft.
Published 2000-02-23 · Modified
7.6EPSS 0.092
CVE-2024-26204
Outlook for Android Information Disclosure Vulnerability
Published 2024-03-12 · Analyzed
7.5EPSS 0.021
CVE-2025-29805
Outlook for Android Information Disclosure Vulnerability
Published 2025-04-08 · Analyzed
7.5EPSS 0.015
CVE-2026-42893
Microsoft Outlook for iOS Tampering Vulnerability
Published 2026-05-12 · Analyzed
7.5EPSS 0.007
CVE-2026-26133
M365 Copilot Information Disclosure Vulnerability
Published 2026-03-13 · Modified
7.1EPSS 0.005
CVE-2019-1084
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by validating display names upon creation in Microsoft Exchange, and by rendering invalid display names correctly in Microsoft Outlook clients., aka 'Microsoft Exchange Information Disclosure Vulnerability'.
Published 2019-07-15 · Modified
6.5EPSS 0.053
CVE-2024-43482
Microsoft Outlook for iOS Information Disclosure Vulnerability
Published 2024-09-10 · Analyzed
6.5EPSS 0.011
CVE-2022-24480
Outlook for Android Elevation of Privilege Vulnerability
Published 2022-12-13 · Modified
6.3EPSS 0.006
CVE-2019-1218
Outlook iOS Spoofing Vulnerability
Published 2019-08-14 · Modified
5.4EPSS 0.039
CVE-2019-1105
Outlook for Android Spoofing Vulnerability
Published 2019-07-29 · Modified
5.4EPSS 0.018
CVE-2025-21259
Microsoft Outlook Spoofing Vulnerability
Published 2025-02-11 · Analyzed
5.3EPSS 0.012
CVE-2006-6659
The Microsoft Office Outlook Recipient ActiveX control (ole32.dll) in Windows XP SP2 allows remote attackers to cause a denial of service (Internet Explorer 7 hang) via crafted HTML.
Published 2006-12-20 · Modified
5.02 PoCEPSS 0.176
CVE-2000-0216
Microsoft email clients in Outlook, Exchange, and Windows Messaging automatically respond to Read Receipt and Delivery Receipt tags, which could allow an attacker to flood a mail system with responses by forging a Read Receipt request that is redirected to a large distribution list.
Published 2000-03-22 · Modified
5.0EPSS 0.051
CVE-2019-1460
A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages, aka 'Outlook for Android Spoofing Vulnerability'.
Published 2020-01-24 · Modified
4.6EPSS 0.014