Skip to main content

Vendor/product archive

microsoft / outlook_express CVEs

Beta · best-effort

44 CVEs tagged to microsoft / outlook_express4 Critical, 13 High, 26 Medium, 1 Low, 0 Unrated.

CVE-2010-0816

Published May 12, 2010

Integer overflow in inetcomm.dll in Microsoft Outlook Express 5.5 SP2, 6, and 6 SP1; Windows Live Mail on Windows XP SP2 and SP3, Windows Vista SP1 and SP2, Windows Server 2008 Go…

CVSS 9.3 · Critical

CVE-2008-5424

Published Dec 11, 2008

The MimeOleClearDirtyTree function in InetComm.dll in Microsoft Outlook Express 6.00.2900.5512 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts an…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2386

Published Dec 13, 2006

Unspecified vulnerability in Microsoft Outlook Express 6 and earlier allows remote attackers to execute arbitrary code via a crafted contact record in a Windows Address Book (WAB)…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2111

Published May 1, 2006

A component in Microsoft Outlook Express 6 allows remote attackers to bypass domain restrictions and obtain sensitive information via redirections with the mhtml: URI handler, as…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0014

Published Apr 12, 2006

Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2226

Published Jul 12, 2005

Microsoft Outlook Express 6.0 leaks the default news server account when a user responds to a "watched" conversation thread, which could allow remote attackers to obtain sensitive…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1213

Published Jun 14, 2005

Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows remote malicious NNTP servers to execute arbitrary code via a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-2137

Published Dec 31, 2004

Outlook Express 6.0, when sending multipart e-mail messages using the "Break apart messages larger than" setting, leaks the BCC recipients of the message to the addresses listed i…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2694

Published Dec 31, 2004

Microsoft Outlook Express 6.0 allows remote attackers to bypass intended access restrictions, load content from arbitrary sources into the Outlook context, and facilitate phishing…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0380

Published May 4, 2004

The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2003-0301

Published Jun 16, 2003

The IMAP Client for Outlook Express 6.00.2800.1106 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause eithe…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2164

Published Dec 31, 2002

Buffer overflow in Microsoft Outlook Express 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (crash) via a long <A HREF> link.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2202

Published Dec 31, 2002

Outlook Express 6.0 does not delete messages from dbx files, even when a user empties the Deleted items folder, which allows local users to read other users email.

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2002-1179

Published Oct 28, 2002

Buffer overflow in the S/MIME Parsing capability in Microsoft Outlook Express 5.5 and 6.0 allows remote attackers to execute arbitrary code via a digitally signed email with a lon…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0862

Published Oct 4, 2002

The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 throu…

CVSS 6.8 · Medium
Showing 1-25 of 44 CVEsPage 1 of 2