VYPR

Outlook

by Microsoft

CVEs (151)

  • CVE-2019-0560MedJan 8, 2019
    risk 0.36cvss 5.5epss 0.09

    An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, aka "Microsoft Office Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office.

  • CVE-2017-8508MedJun 15, 2017
    risk 0.36cvss 5.5epss 0.04

    A security feature bypass vulnerability exists in Microsoft Office software when it improperly handles the parsing of file formats, aka "Microsoft Office Security Feature Bypass Vulnerability".

  • CVE-2025-21259MedFeb 11, 2025
    risk 0.35cvss 5.3epss 0.01

    Microsoft Outlook Spoofing Vulnerability

  • CVE-2022-23280MedFeb 9, 2022
    risk 0.35cvss 5.3epss 0.02

    Microsoft Outlook for Mac Security Feature Bypass Vulnerability

  • CVE-2019-1218MedAug 14, 2019
    risk 0.35cvss 5.4epss 0.04

    A spoofing vulnerability exists in the way Microsoft Outlook iOS software parses specifically crafted email messages. An authenticated attacker could exploit the vulnerability by sending a specially crafted email message to a victim. The attacker who successfully exploited this…

  • CVE-2019-1105MedJul 29, 2019
    risk 0.35cvss 5.4epss 0.02

    A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages. An authenticated attacker could exploit the vulnerability by sending a specially crafted email message to a victim. The attacker who successfully…

  • CVE-2020-1483MedAug 17, 2020
    risk 0.33cvss 5.0epss 0.09

    A remote code execution vulnerability exists in Microsoft Outlook when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on…

  • CVE-2020-16949MedOct 16, 2020
    risk 0.31cvss 4.7epss 0.03

    A denial of service vulnerability exists in Microsoft Outlook software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could cause a remote denial of service against a system. Exploitation of the…

  • CVE-2019-1460MedJan 24, 2020
    risk 0.30cvss 4.6epss 0.01

    A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages, aka 'Outlook for Android Spoofing Vulnerability'.

  • CVE-2026-62882MedAug 11, 2026
    risk 0.28cvss 4.3epss 0.01

    Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2020-1229MedJun 9, 2020
    risk 0.28cvss 4.3epss 0.04

    A security feature bypass vulnerability exists in Microsoft Outlook when Office fails to enforce security settings configured on a system, aka 'Microsoft Outlook Security Feature Bypass Vulnerability'.

  • CVE-2019-1204MedAug 14, 2019
    risk 0.28cvss 4.3epss 0.04

    An elevation of privilege vulnerability exists when Microsoft Outlook initiates processing of incoming messages without sufficient validation of the formatting of the messages. An attacker who successfully exploited the vulnerability could attempt to force Outlook to load a…

  • CVE-2004-0204Aug 6, 2004
    risk 0.09cvss epss 0.73

    Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows…

  • CVE-2006-4868Sep 19, 2006
    risk 0.08cvss epss 0.60

    Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft Outlook and Internet Explorer 6.0 on Windows XP SP2, and possibly other versions, allows remote attackers to execute arbitrary code via a Vector Markup Language (VML) file with a…

  • CVE-2010-0266Jul 15, 2010
    risk 0.07cvss epss 0.55

    Microsoft Office Outlook 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 does not properly verify e-mail attachments with a PR_ATTACH_METHOD property value of ATTACH_BY_REFERENCE, which allows user-assisted remote attackers to execute arbitrary code via a crafted message, aka…

  • CVE-2004-0200Sep 28, 2004
    risk 0.07cvss epss 0.49

    Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length…

  • CVE-2004-0121Apr 15, 2004
    risk 0.07cvss epss 0.48

    Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.

  • CVE-2001-0538Aug 14, 2001
    risk 0.07cvss epss 0.53

    Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page.

  • CVE-2000-0567Jul 18, 2000
    risk 0.06cvss epss 0.32

    Buffer overflow in Microsoft Outlook and Outlook Express allows remote attackers to execute arbitrary commands via a long Date field in an email header, aka the "Malformed E-mail Header" vulnerability.

  • CVE-2004-0502Aug 18, 2004
    risk 0.05cvss epss 0.20

    Outlook 2003, when replying to an e-mail message, stores certain files in a predictable location for the "src" of an img tag of the original message, which allows remote attackers to bypass zone restrictions and exploit other issues that rely on predictable locations, as…

Page 5 of 8