Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Filtered by product Outlook
Total 114 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-1164 1 Microsoft 2 Outlook, Outlook Express 2025-04-03 5.0 MEDIUM N/A
Microsoft Outlook client allows remote attackers to cause a denial of service by sending multiple email messages with the same X-UIDL headers, which causes Outlook to hang.
CVE-2006-2055 1 Microsoft 1 Outlook 2025-04-03 5.0 MEDIUM N/A
Argument injection vulnerability in Microsoft Outlook 2003 SP1 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment. NOTE: it is not clear whether this issue is implementation-specific or a problem in the Microsoft API.
CVE-2000-0329 1 Microsoft 4 Ie, Internet Explorer, Outlook and 1 more 2025-04-03 5.1 MEDIUM N/A
A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an attachment and an embedded script in an HTML mail, aka the "Active Setup Control" vulnerability.
CVE-2001-1088 1 Microsoft 2 Outlook, Outlook Express 2025-04-03 7.5 HIGH N/A
Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the "Automatically put people I reply to in my address book" option enabled, do not notify the user when the "Reply-To" address is different than the "From" address, which could allow an untrusted remote attacker to spoof legitimate addresses and intercept email from the client that is intended for another user.
CVE-2004-0526 1 Microsoft 4 Ie, Internet Explorer, Outlook and 1 more 2025-04-03 5.0 MEDIUM N/A
Unknown versions of Internet Explorer and Outlook allow remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.
CVE-2004-0121 1 Microsoft 2 Office, Outlook 2025-04-03 7.5 HIGH N/A
Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.
CVE-2023-23397 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2025-03-13 N/A 9.8 CRITICAL
Microsoft Outlook Elevation of Privilege Vulnerability
CVE-2023-33131 1 Microsoft 4 Office, Office Long Term Servicing Channel, Outlook and 1 more 2025-02-28 N/A 8.8 HIGH
Microsoft Outlook Remote Code Execution Vulnerability
CVE-2021-31949 1 Microsoft 3 365 Apps, Office, Outlook 2025-02-28 6.8 MEDIUM 7.3 HIGH
Microsoft Outlook Remote Code Execution Vulnerability
CVE-2025-21259 1 Microsoft 1 Outlook 2025-02-28 N/A 5.3 MEDIUM
Microsoft Outlook Spoofing Vulnerability
CVE-2023-35311 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2025-02-24 N/A 8.8 HIGH
Microsoft Outlook Security Feature Bypass Vulnerability
CVE-2025-21357 1 Microsoft 3 365 Apps, Office, Outlook 2025-01-21 N/A 6.7 MEDIUM
Microsoft Outlook Remote Code Execution Vulnerability
CVE-2025-21361 1 Microsoft 2 Office, Outlook 2025-01-17 N/A 7.8 HIGH
Microsoft Outlook Remote Code Execution Vulnerability
CVE-2024-26204 1 Microsoft 1 Outlook 2025-01-15 N/A 7.5 HIGH
Outlook for Android Information Disclosure Vulnerability
CVE-2024-20670 1 Microsoft 2 Outlook, Windows 2025-01-08 N/A 8.1 HIGH
Outlook for Windows Spoofing Vulnerability
CVE-2022-24480 1 Microsoft 1 Outlook 2025-01-02 N/A 6.3 MEDIUM
Outlook for Android Elevation of Privilege Vulnerability
CVE-2024-38020 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2024-11-21 N/A 6.5 MEDIUM
Microsoft Outlook Spoofing Vulnerability
CVE-2024-30103 1 Microsoft 3 365 Apps, Office, Outlook 2024-11-21 N/A 8.8 HIGH
Microsoft Outlook Remote Code Execution Vulnerability
CVE-2024-21378 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2024-11-21 N/A 8.8 HIGH
Microsoft Outlook Remote Code Execution Vulnerability
CVE-2023-36893 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2024-11-21 N/A 6.5 MEDIUM
Microsoft Outlook Spoofing Vulnerability