VYPR

Outlook

by Microsoft

CVEs (151)

  • CVE-2019-1084MedJul 15, 2019
    risk 0.43cvss 6.5epss 0.05

    An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to…

  • CVE-2019-0559MedJan 8, 2019
    risk 0.43cvss 6.5epss 0.07

    An information disclosure vulnerability exists when Microsoft Outlook improperly handles certain types of messages, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook.

  • CVE-2018-8579MedNov 14, 2018
    risk 0.43cvss 6.5epss 0.06

    An information disclosure vulnerability exists when attaching files to Outlook messages, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office. This CVE ID is unique from CVE-2018-8558.

  • CVE-2018-8558MedNov 14, 2018
    risk 0.43cvss 6.5epss 0.06

    An information disclosure vulnerability exists when Microsoft Outlook fails to respect "Default link type" settings configured via the SharePoint Online Admin Center, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office.…

  • CVE-2018-8244MedJun 14, 2018
    risk 0.43cvss 6.5epss 0.05

    An elevation of privilege vulnerability exists when Microsoft Outlook does not validate attachment headers properly, aka "Microsoft Outlook Elevation of Privilege Vulnerability." This affects Microsoft Office, Microsoft Outlook.

  • CVE-2018-8160MedMay 9, 2018
    risk 0.43cvss 6.5epss 0.09

    An information disclosure vulnerability exists in Outlook when a message is opened, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Word, Microsoft Office.

  • CVE-2018-8150MedMay 9, 2018
    risk 0.43cvss 6.5epss 0.05

    A security feature bypass vulnerability exists when the Microsoft Outlook attachment block filter does not properly handle attachments, aka "Microsoft Outlook Security Feature Bypass Vulnerability." This affects Microsoft Office.

  • CVE-2018-0850MedFeb 15, 2018
    risk 0.43cvss 6.5epss 0.05

    Microsoft Outlook 2007, Microsoft Outlook 2010, Microsoft Outlook 2013, Microsoft Outlook 2016, and Microsoft Office 2016 Click-to-Run allow an elevation of privilege vulnerability due to how the format of incoming message is validated, aka "Microsoft Outlook Elevation of…

  • CVE-2017-8545MedJun 15, 2017
    risk 0.43cvss 6.5epss 0.05

    A spoofing vulnerability exists in when Microsoft Outlook for Mac does not sanitize html properly, aka "Microsoft Outlook for Mac Spoofing Vulnerability".

  • CVE-2017-0207MedApr 12, 2017
    risk 0.43cvss 6.5epss 0.10

    Microsoft Outlook for Mac 2011 allows remote attackers to spoof web content via a crafted email with specific HTML tags, aka "Microsoft Browser Spoofing Vulnerability."

  • CVE-2024-43482MedSep 10, 2024
    risk 0.42cvss 6.5epss 0.01

    Microsoft Outlook for iOS Information Disclosure Vulnerability

  • CVE-2024-38020MedJul 9, 2024
    risk 0.42cvss 6.5epss 0.02

    Microsoft Outlook Spoofing Vulnerability

  • CVE-2023-36893MedAug 8, 2023
    risk 0.42cvss 6.5epss 0.02

    Microsoft Outlook Spoofing Vulnerability

  • CVE-2022-24480MedDec 13, 2022
    risk 0.41cvss 6.3epss 0.01

    Outlook for Android Elevation of Privilege Vulnerability

  • CVE-2017-17689MedMay 16, 2018
    risk 0.39cvss 5.9epss 0.04

    The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

  • CVE-2017-17688MedMay 16, 2018
    risk 0.39cvss 5.9epss 0.06

    The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature…

  • CVE-2024-43604MedOct 8, 2024
    risk 0.37cvss 5.7epss 0.01

    Outlook for Android Elevation of Privilege Vulnerability

  • CVE-2017-8572MedAug 1, 2017
    risk 0.37cvss 5.5epss 0.13

    Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 2016 as packaged in Microsoft Office allows an information disclosure vulnerability due to the way that it discloses the contents of its memory, aka "Microsoft Office Outlook…

  • CVE-2017-0204MedApr 12, 2017
    risk 0.37cvss 5.5epss 0.19

    Microsoft Outlook 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1, and Microsoft Outlook 2016 allow remote attackers to bypass the Office Protected View via a specially crafted document, aka "Microsoft Office Security Feature Bypass Vulnerability."

  • CVE-2020-1493MedAug 17, 2020
    risk 0.36cvss 5.5epss 0.07

    An information disclosure vulnerability exists when attaching files to Outlook messages. This vulnerability could potentially allow users to share attached files such that they are accessible by anonymous users where they should be restricted to specific users. To exploit this…

Page 4 of 8