Outlook
by Microsoft
CVEs (151)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-1084 | Med | 0.43 | 6.5 | 0.05 | Jul 15, 2019 | An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to… | ||
| CVE-2019-0559 | Med | 0.43 | 6.5 | 0.07 | Jan 8, 2019 | An information disclosure vulnerability exists when Microsoft Outlook improperly handles certain types of messages, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook. | ||
| CVE-2018-8579 | Med | 0.43 | 6.5 | 0.06 | Nov 14, 2018 | An information disclosure vulnerability exists when attaching files to Outlook messages, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office. This CVE ID is unique from CVE-2018-8558. | ||
| CVE-2018-8558 | Med | 0.43 | 6.5 | 0.06 | Nov 14, 2018 | An information disclosure vulnerability exists when Microsoft Outlook fails to respect "Default link type" settings configured via the SharePoint Online Admin Center, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office.… | ||
| CVE-2018-8244 | Med | 0.43 | 6.5 | 0.05 | Jun 14, 2018 | An elevation of privilege vulnerability exists when Microsoft Outlook does not validate attachment headers properly, aka "Microsoft Outlook Elevation of Privilege Vulnerability." This affects Microsoft Office, Microsoft Outlook. | ||
| CVE-2018-8160 | Med | 0.43 | 6.5 | 0.09 | May 9, 2018 | An information disclosure vulnerability exists in Outlook when a message is opened, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Word, Microsoft Office. | ||
| CVE-2018-8150 | Med | 0.43 | 6.5 | 0.05 | May 9, 2018 | A security feature bypass vulnerability exists when the Microsoft Outlook attachment block filter does not properly handle attachments, aka "Microsoft Outlook Security Feature Bypass Vulnerability." This affects Microsoft Office. | ||
| CVE-2018-0850 | Med | 0.43 | 6.5 | 0.05 | Feb 15, 2018 | Microsoft Outlook 2007, Microsoft Outlook 2010, Microsoft Outlook 2013, Microsoft Outlook 2016, and Microsoft Office 2016 Click-to-Run allow an elevation of privilege vulnerability due to how the format of incoming message is validated, aka "Microsoft Outlook Elevation of… | ||
| CVE-2017-8545 | Med | 0.43 | 6.5 | 0.05 | Jun 15, 2017 | A spoofing vulnerability exists in when Microsoft Outlook for Mac does not sanitize html properly, aka "Microsoft Outlook for Mac Spoofing Vulnerability". | ||
| CVE-2017-0207 | Med | 0.43 | 6.5 | 0.10 | Apr 12, 2017 | Microsoft Outlook for Mac 2011 allows remote attackers to spoof web content via a crafted email with specific HTML tags, aka "Microsoft Browser Spoofing Vulnerability." | ||
| CVE-2024-43482 | Med | 0.42 | 6.5 | 0.01 | Sep 10, 2024 | Microsoft Outlook for iOS Information Disclosure Vulnerability | ||
| CVE-2024-38020 | Med | 0.42 | 6.5 | 0.02 | Jul 9, 2024 | Microsoft Outlook Spoofing Vulnerability | ||
| CVE-2023-36893 | Med | 0.42 | 6.5 | 0.02 | Aug 8, 2023 | Microsoft Outlook Spoofing Vulnerability | ||
| CVE-2022-24480 | Med | 0.41 | 6.3 | 0.01 | Dec 13, 2022 | Outlook for Android Elevation of Privilege Vulnerability | ||
| CVE-2017-17689 | Med | 0.39 | 5.9 | 0.04 | May 16, 2018 | The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. | ||
| CVE-2017-17688 | Med | 0.39 | 5.9 | 0.06 | May 16, 2018 | The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature… | ||
| CVE-2024-43604 | Med | 0.37 | 5.7 | 0.01 | Oct 8, 2024 | Outlook for Android Elevation of Privilege Vulnerability | ||
| CVE-2017-8572 | Med | 0.37 | 5.5 | 0.13 | Aug 1, 2017 | Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 2016 as packaged in Microsoft Office allows an information disclosure vulnerability due to the way that it discloses the contents of its memory, aka "Microsoft Office Outlook… | ||
| CVE-2017-0204 | Med | 0.37 | 5.5 | 0.19 | Apr 12, 2017 | Microsoft Outlook 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1, and Microsoft Outlook 2016 allow remote attackers to bypass the Office Protected View via a specially crafted document, aka "Microsoft Office Security Feature Bypass Vulnerability." | ||
| CVE-2020-1493 | Med | 0.36 | 5.5 | 0.07 | Aug 17, 2020 | An information disclosure vulnerability exists when attaching files to Outlook messages. This vulnerability could potentially allow users to share attached files such that they are accessible by anonymous users where they should be restricted to specific users. To exploit this… |
- risk 0.43cvss 6.5epss 0.05
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to…
- risk 0.43cvss 6.5epss 0.07
An information disclosure vulnerability exists when Microsoft Outlook improperly handles certain types of messages, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook.
- risk 0.43cvss 6.5epss 0.06
An information disclosure vulnerability exists when attaching files to Outlook messages, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office. This CVE ID is unique from CVE-2018-8558.
- risk 0.43cvss 6.5epss 0.06
An information disclosure vulnerability exists when Microsoft Outlook fails to respect "Default link type" settings configured via the SharePoint Online Admin Center, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office.…
- risk 0.43cvss 6.5epss 0.05
An elevation of privilege vulnerability exists when Microsoft Outlook does not validate attachment headers properly, aka "Microsoft Outlook Elevation of Privilege Vulnerability." This affects Microsoft Office, Microsoft Outlook.
- risk 0.43cvss 6.5epss 0.09
An information disclosure vulnerability exists in Outlook when a message is opened, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Word, Microsoft Office.
- risk 0.43cvss 6.5epss 0.05
A security feature bypass vulnerability exists when the Microsoft Outlook attachment block filter does not properly handle attachments, aka "Microsoft Outlook Security Feature Bypass Vulnerability." This affects Microsoft Office.
- risk 0.43cvss 6.5epss 0.05
Microsoft Outlook 2007, Microsoft Outlook 2010, Microsoft Outlook 2013, Microsoft Outlook 2016, and Microsoft Office 2016 Click-to-Run allow an elevation of privilege vulnerability due to how the format of incoming message is validated, aka "Microsoft Outlook Elevation of…
- risk 0.43cvss 6.5epss 0.05
A spoofing vulnerability exists in when Microsoft Outlook for Mac does not sanitize html properly, aka "Microsoft Outlook for Mac Spoofing Vulnerability".
- risk 0.43cvss 6.5epss 0.10
Microsoft Outlook for Mac 2011 allows remote attackers to spoof web content via a crafted email with specific HTML tags, aka "Microsoft Browser Spoofing Vulnerability."
- risk 0.42cvss 6.5epss 0.01
Microsoft Outlook for iOS Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.02
Microsoft Outlook Spoofing Vulnerability
- risk 0.42cvss 6.5epss 0.02
Microsoft Outlook Spoofing Vulnerability
- risk 0.41cvss 6.3epss 0.01
Outlook for Android Elevation of Privilege Vulnerability
- risk 0.39cvss 5.9epss 0.04
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
- risk 0.39cvss 5.9epss 0.06
The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature…
- risk 0.37cvss 5.7epss 0.01
Outlook for Android Elevation of Privilege Vulnerability
- risk 0.37cvss 5.5epss 0.13
Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 2016 as packaged in Microsoft Office allows an information disclosure vulnerability due to the way that it discloses the contents of its memory, aka "Microsoft Office Outlook…
- risk 0.37cvss 5.5epss 0.19
Microsoft Outlook 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1, and Microsoft Outlook 2016 allow remote attackers to bypass the Office Protected View via a specially crafted document, aka "Microsoft Office Security Feature Bypass Vulnerability."
- risk 0.36cvss 5.5epss 0.07
An information disclosure vulnerability exists when attaching files to Outlook messages. This vulnerability could potentially allow users to share attached files such that they are accessible by anonymous users where they should be restricted to specific users. To exploit this…
Page 4 of 8