- EPSS 63.06%
- Published 14.08.2001 04:00:00
- Last modified 03.04.2025 01:03:51
Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page.
CVE-2001-1088
- EPSS 35.4%
- Published 05.06.2001 04:00:00
- Last modified 03.04.2025 01:03:51
Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the "Automatically put people I reply to in my address book" option enabled, do not notify the user when the "Reply-To" address is different than the "From" address, which cou...
- EPSS 13.45%
- Published 02.06.2001 04:00:00
- Last modified 03.04.2025 01:03:51
MSHTML.DLL HTML parser in Internet Explorer 4.0, and other versions, allows remote attackers to cause a denial of service (application crash) via a script that creates and deletes an object that is associated with the browser window object.
CVE-2001-0145
- EPSS 11.76%
- Published 03.05.2001 04:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in VCard handler in Outlook 2000 and 98, and Outlook Express 5.x, allows an attacker to execute arbitrary commands via a malformed vCard birthday field.
- EPSS 18.5%
- Published 20.10.2000 04:00:00
- Last modified 03.04.2025 01:03:51
The Microsoft Outlook mail client identifies the physical path of the sender's machine within a winmail.dat attachment to Rich Text Format (RTF) files.
- EPSS 11.68%
- Published 20.10.2000 04:00:00
- Last modified 03.04.2025 01:03:51
Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service.
CVE-2000-0621
- EPSS 5.84%
- Published 20.07.2000 04:00:00
- Last modified 03.04.2025 01:03:51
Microsoft Outlook 98 and 2000, and Outlook Express 4.0x and 5.0x, allow remote attackers to read files on the client's system via a malformed HTML message that stores files outside of the cache, aka the "Cache Bypass" vulnerability.
- EPSS 19.9%
- Published 18.07.2000 04:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in Microsoft Outlook and Outlook Express allows remote attackers to execute arbitrary commands via a long Date field in an email header, aka the "Malformed E-mail Header" vulnerability.
- EPSS 15.51%
- Published 05.06.2000 04:00:00
- Last modified 03.04.2025 01:03:51
Microsoft Outlook and Outlook Express allow remote attackers to cause a denial of service by sending email messages with blank fields such as BCC, Reply-To, Return-Path, or From.
- EPSS 11.72%
- Published 12.05.2000 04:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in Outlook Express 4.x allows attackers to cause a denial of service via a mail or news message that has a .jpg or .bmp attachment with a long file name.