Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Filtered by product Outlook Express
Total 45 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-0322 1 Microsoft 3 Internet Explorer, Outlook, Outlook Express 2025-04-03 5.0 MEDIUM N/A
MSHTML.DLL HTML parser in Internet Explorer 4.0, and other versions, allows remote attackers to cause a denial of service (application crash) via a script that creates and deletes an object that is associated with the browser window object.
CVE-2004-0380 1 Microsoft 1 Outlook Express 2025-04-03 10.0 HIGH N/A
The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability."
CVE-2002-0285 1 Microsoft 1 Outlook Express 2025-04-03 7.5 HIGH N/A
Outlook Express 5.5 and 6.0 on Windows treats a carriage return ("CR") in a message header as if it were a valid carriage return/line feed combination (CR/LF), which could allow remote attackers to bypass virus protection and or other filtering mechanisms via a mail message with headers that only contain the CR, which causes Outlook to create separate headers.
CVE-2000-0653 1 Microsoft 1 Outlook Express 2025-04-03 5.0 MEDIUM N/A
Microsoft Outlook Express allows remote attackers to monitor a user's email by creating a persistent browser link to the Outlook Express windows, aka the "Persistent Mail-Browser Link" vulnerability.
CVE-2005-1213 1 Microsoft 1 Outlook Express 2025-04-03 7.5 HIGH N/A
Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows remote malicious NNTP servers to execute arbitrary code via a LIST response with a long second field.