Vulnerabilities > Microsoft > Outlook Express > Critical

DATE CVE VULNERABILITY TITLE RISK
2007-10-09 CVE-2007-3897 Buffer Errors vulnerability in Microsoft Outlook Express and Windows Mail
Heap-based buffer overflow in Microsoft Outlook Express 6 and earlier, and Windows Mail for Vista, allows remote Network News Transfer Protocol (NNTP) servers to execute arbitrary code via long NNTP responses that trigger memory corruption.
network
microsoft CWE-119
critical
9.3
2004-05-04 CVE-2004-0380 Unspecified vulnerability in Microsoft Outlook Express 5.5/6.0
The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability."
network
low complexity
microsoft
critical
10.0
1997-11-01 CVE-1999-0967 Unspecified vulnerability in Microsoft products
Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol.
network
low complexity
microsoft
critical
10.0