- EPSS 14.65%
- Veröffentlicht 13.11.2013 00:55:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
Microsoft Outlook 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT does not properly expand metadata contained in S/MIME certificates, which allows remote attackers to obtain sensitive network configuration and state information via a crafted certificat...
CVE-2013-3870
- EPSS 36.72%
- Veröffentlicht 11.09.2013 14:03:48
- Zuletzt bearbeitet 29.04.2026 01:13:23
Double free vulnerability in Microsoft Outlook 2007 SP3 and 2010 SP1 and SP2 allows remote attackers to execute arbitrary code by including many nested S/MIME certificates in an e-mail message, aka "Message Certificate Vulnerability."
CVE-2010-2728
- EPSS 28.37%
- Veröffentlicht 15.09.2010 19:00:19
- Zuletzt bearbeitet 29.04.2026 01:13:23
Heap-based buffer overflow in Microsoft Outlook 2002 SP3, 2003 SP3, and 2007 SP2, when Online Mode for an Exchange Server is enabled, allows remote attackers to execute arbitrary code via a crafted e-mail message, aka "Heap Based Buffer Overflow in O...
CVE-2010-0266
- EPSS 82.8%
- Veröffentlicht 15.07.2010 12:57:12
- Zuletzt bearbeitet 29.04.2026 01:13:23
Microsoft Office Outlook 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 does not properly verify e-mail attachments with a PR_ATTACH_METHOD property value of ATTACH_BY_REFERENCE, which allows user-assisted remote attackers to execute arbitrary code via a c...
CVE-2008-3068
- EPSS 12.63%
- Veröffentlicht 07.07.2008 23:41:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) si...
CVE-2007-4040
- EPSS 16.8%
- Veröffentlicht 27.07.2007 22:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Argument injection vulnerability involving Microsoft Outlook and Outlook Express, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspe...
CVE-2007-0671
- EPSS 55.49%
- Veröffentlicht 03.02.2007 01:28:00
- Zuletzt bearbeitet 22.04.2026 13:52:33
Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in tar...
CVE-2007-0033
- EPSS 59.74%
- Veröffentlicht 09.01.2007 23:28:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Microsoft Outlook 2002 and 2003 allows user-assisted remote attackers to execute arbitrary code via a malformed VEVENT record in an .iCal meeting request or ICS file.
CVE-2007-0034
- EPSS 62.93%
- Veröffentlicht 09.01.2007 23:28:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Buffer overflow in the Advanced Search (Finder.exe) feature of Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted Outlook Saved Searches (OSS) file that triggers memory corruption, aka...
CVE-2006-1305
- EPSS 51.83%
- Veröffentlicht 31.12.2006 05:00:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to cause a denial of service (memory exhaustion and interrupted mail recovery) via malformed e-mail header information, possibly related to (1) long subject lines or (2) lar...