VYPR

Outlook

by Microsoft

CVEs (151)

  • CVE-2025-29805HigApr 8, 2025
    risk 0.49cvss 7.5epss 0.01

    Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a network.

  • CVE-2024-26204HigMar 12, 2024
    risk 0.49cvss 7.5epss 0.02

    Outlook for Android Information Disclosure Vulnerability

  • CVE-2023-36763HigSep 12, 2023
    risk 0.49cvss 7.5epss 0.02

    Microsoft Outlook Information Disclosure Vulnerability

  • CVE-2018-8310HigJul 11, 2018
    risk 0.49cvss 7.5epss 0.05

    A tampering vulnerability exists when Microsoft Outlook does not properly handle specific attachment types when rendering HTML emails, aka "Microsoft Office Tampering Vulnerability." This affects Microsoft Word, Microsoft Office.

  • CVE-2026-42893HigMay 12, 2026
    risk 0.48cvss 7.4epss 0.00

    Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network.

  • CVE-2021-31949HigJun 8, 2021
    risk 0.48cvss 7.3epss 0.03

    Microsoft Outlook Remote Code Execution Vulnerability

  • CVE-2025-47171MedJun 10, 2025
    risk 0.47cvss 6.7epss 0.02

    Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.

  • CVE-2026-26133HigMar 16, 2026
    risk 0.46cvss 7.1epss 0.00

    AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-49699HigJul 8, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2024-42220HigDec 18, 2024
    risk 0.46cvss 7.1epss 0.01

    A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this…

  • CVE-2024-21402HigFeb 13, 2024
    risk 0.46cvss 7.1epss 0.00

    Microsoft Outlook Elevation of Privilege Vulnerability

  • CVE-2021-28452HigApr 13, 2021
    risk 0.46cvss 7.1epss 0.01

    Microsoft Outlook Memory Corruption Vulnerability

  • CVE-2025-21357MedJan 14, 2025
    risk 0.44cvss 6.7epss 0.01

    Microsoft Outlook Remote Code Execution Vulnerability

  • CVE-2024-38173MedAug 13, 2024
    risk 0.44cvss 6.7epss 0.01

    Microsoft Outlook Remote Code Execution Vulnerability

  • CVE-2023-35636MedDec 12, 2023
    risk 0.44cvss 6.5epss 0.18

    Microsoft Outlook Information Disclosure Vulnerability

  • CVE-2023-33153MedJul 11, 2023
    risk 0.44cvss 6.8epss 0.01

    Microsoft Outlook Remote Code Execution Vulnerability

  • CVE-2016-3366MedSep 14, 2016
    risk 0.44cvss 6.5epss 0.16

    Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, Outlook 2016, and Outlook 2016 for Mac do not properly implement RFC 2046, which allows remote attackers to bypass virus or spam detection via crafted MIME data in an e-mail attachment, aka…

  • CVE-2023-33151MedJul 11, 2023
    risk 0.43cvss 6.5epss 0.03

    Microsoft Outlook Spoofing Vulnerability

  • CVE-2020-17119MedDec 10, 2020
    risk 0.43cvss 6.5epss 0.04

    Microsoft Outlook Information Disclosure Vulnerability

  • CVE-2020-0696MedFeb 11, 2020
    risk 0.43cvss 6.5epss 0.05

    A security feature bypass vulnerability exists in Microsoft Outlook software when it improperly handles the parsing of URI formats, aka 'Microsoft Outlook Security Feature Bypass Vulnerability'.

Page 3 of 8