Outlook
by Microsoft
CVEs (151)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-21413 | Cri | 0.83 | 9.8 | 0.95 | KEV | Feb 13, 2024 | Microsoft Outlook Remote Code Execution Vulnerability | |
| CVE-2023-23397 | Cri | 0.83 | 9.8 | 0.97 | KEV | Mar 14, 2023 | Microsoft Outlook Elevation of Privilege Vulnerability | |
| CVE-2007-0671 | Hig | 0.73 | 8.8 | 0.42 | KEV | Feb 3, 2007 | Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks. | |
| CVE-2023-35311 | Hig | 0.70 | 8.8 | 0.16 | KEV | Jul 11, 2023 | Microsoft Outlook Security Feature Bypass Vulnerability | |
| CVE-2015-1641 | Hig | 0.70 | 7.8 | 0.93 | KEV | Apr 14, 2015 | Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office Web Apps Server 2010 SP2 and 2013 SP1 allow remote… | |
| CVE-2017-11774 | Hig | 0.67 | 7.8 | 0.60 | KEV | Oct 13, 2017 | Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Office handles objects in memory, aka "Microsoft Outlook Security Feature Bypass Vulnerability." | |
| CVE-2023-33131 | Hig | 0.61 | 8.8 | 0.06 | Jun 14, 2023 | Microsoft Outlook Remote Code Execution Vulnerability | ||
| CVE-2018-8582 | Hig | 0.59 | 8.8 | 0.19 | Nov 14, 2018 | A remote code execution vulnerability exists in the way that Microsoft Outlook parses specially modified rule export files, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook. This CVE ID is unique… | ||
| CVE-2018-0852 | Hig | 0.59 | 8.8 | 0.19 | Feb 15, 2018 | Microsoft Outlook 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1 and RT SP1, Microsoft Outlook 2016, and Microsoft Office 2016 Click-to-Run (C2R) allow a remote code execution vulnerability, due to how Outlook handles objects in memory, aka "Microsoft Office… | ||
| CVE-2018-0851 | Hig | 0.59 | 8.8 | 0.19 | Feb 15, 2018 | Microsoft Office 2007 SP2, Microsoft Office Word Viewer, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1 and RT SP1, Microsoft Office 2016, and Microsoft Office 2016 Click-to-Run (C2R) allow a remote code execution vulnerability, due to how Office handles objects in memory,… | ||
| CVE-2024-21378 | Hig | 0.58 | 8.8 | 0.11 | Feb 13, 2024 | Microsoft Outlook Remote Code Execution Vulnerability | ||
| CVE-2020-0760 | Hig | 0.58 | 8.8 | 0.09 | Apr 15, 2020 | A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries, aka 'Microsoft Office Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0991. | ||
| CVE-2007-4040 | Hig | 0.58 | 8.8 | 0.13 | Jul 27, 2007 | Argument injection vulnerability involving Microsoft Outlook and Outlook Express, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified URI, which are… | ||
| CVE-2026-70329 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | ||
| CVE-2024-38021 | Hig | 0.57 | 8.8 | 0.04 | Jul 9, 2024 | Microsoft Outlook Remote Code Execution Vulnerability | ||
| CVE-2024-30103 | Hig | 0.57 | 8.8 | 0.03 | Jun 11, 2024 | Microsoft Outlook Remote Code Execution Vulnerability | ||
| CVE-2024-20670 | Hig | 0.53 | 8.1 | 0.02 | Apr 9, 2024 | Outlook for Windows Spoofing Vulnerability | ||
| CVE-2020-1349 | Hig | 0.53 | 7.8 | 0.23 | Jul 14, 2020 | A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka 'Microsoft Outlook Remote Code Execution Vulnerability'. | ||
| CVE-2018-8587 | Hig | 0.53 | 7.8 | 0.29 | Dec 12, 2018 | A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook. | ||
| CVE-2017-8506 | Hig | 0.53 | 7.8 | 0.24 | Jun 15, 2017 | A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8509, CVE-2017-8510, CVE-2017-8511, CVE-2017-8512, and… |
- risk 0.83cvss 9.8epss 0.95
Microsoft Outlook Remote Code Execution Vulnerability
- risk 0.83cvss 9.8epss 0.97
Microsoft Outlook Elevation of Privilege Vulnerability
- risk 0.73cvss 8.8epss 0.42
Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.
- risk 0.70cvss 8.8epss 0.16
Microsoft Outlook Security Feature Bypass Vulnerability
- risk 0.70cvss 7.8epss 0.93
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office Web Apps Server 2010 SP2 and 2013 SP1 allow remote…
- risk 0.67cvss 7.8epss 0.60
Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Office handles objects in memory, aka "Microsoft Outlook Security Feature Bypass Vulnerability."
- risk 0.61cvss 8.8epss 0.06
Microsoft Outlook Remote Code Execution Vulnerability
- risk 0.59cvss 8.8epss 0.19
A remote code execution vulnerability exists in the way that Microsoft Outlook parses specially modified rule export files, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook. This CVE ID is unique…
- risk 0.59cvss 8.8epss 0.19
Microsoft Outlook 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1 and RT SP1, Microsoft Outlook 2016, and Microsoft Office 2016 Click-to-Run (C2R) allow a remote code execution vulnerability, due to how Outlook handles objects in memory, aka "Microsoft Office…
- risk 0.59cvss 8.8epss 0.19
Microsoft Office 2007 SP2, Microsoft Office Word Viewer, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1 and RT SP1, Microsoft Office 2016, and Microsoft Office 2016 Click-to-Run (C2R) allow a remote code execution vulnerability, due to how Office handles objects in memory,…
- risk 0.58cvss 8.8epss 0.11
Microsoft Outlook Remote Code Execution Vulnerability
- risk 0.58cvss 8.8epss 0.09
A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries, aka 'Microsoft Office Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0991.
- risk 0.58cvss 8.8epss 0.13
Argument injection vulnerability involving Microsoft Outlook and Outlook Express, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified URI, which are…
- risk 0.57cvss 8.8epss 0.01
Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.04
Microsoft Outlook Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.03
Microsoft Outlook Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.02
Outlook for Windows Spoofing Vulnerability
- risk 0.53cvss 7.8epss 0.23
A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka 'Microsoft Outlook Remote Code Execution Vulnerability'.
- risk 0.53cvss 7.8epss 0.29
A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook.
- risk 0.53cvss 7.8epss 0.24
A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8509, CVE-2017-8510, CVE-2017-8511, CVE-2017-8512, and…
Page 1 of 8