Vulnerabilities > Microsoft > Outlook

DATE CVE VULNERABILITY TITLE RISK
2007-01-09 CVE-2007-0033 Remote Code Execution vulnerability in Microsoft Outlook VEVENT Record
Microsoft Outlook 2002 and 2003 allows user-assisted remote attackers to execute arbitrary code via a malformed VEVENT record in an .iCal meeting request or ICS file.
network
microsoft
critical
9.3
2006-12-31 CVE-2006-1305 Resource Management Errors vulnerability in Microsoft Office and Outlook
Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to cause a denial of service (memory exhaustion and interrupted mail recovery) via malformed e-mail header information, possibly related to (1) long subject lines or (2) large numbers of recipients in To or CC headers.
network
microsoft CWE-399
4.3
2006-12-20 CVE-2006-6659 Remote Internet Explorer Denial of Service vulnerability in Microsoft IE, Outlook and Windows XP
The Microsoft Office Outlook Recipient ActiveX control (ole32.dll) in Windows XP SP2 allows remote attackers to cause a denial of service (Internet Explorer 7 hang) via crafted HTML.
network
low complexity
microsoft
5.0
2006-10-10 CVE-2006-3877 Code Injection vulnerability in Microsoft products
Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via an unspecified "crafted file," a different vulnerability than CVE-2006-3435, CVE-2006-4694, and CVE-2006-3876.
network
microsoft CWE-94
critical
9.3
2006-09-19 CVE-2006-4868 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft Internet Explorer and Outlook
Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft Outlook and Internet Explorer 6.0 on Windows XP SP2, and possibly other versions, allows remote attackers to execute arbitrary code via a Vector Markup Language (VML) file with a long fill parameter within a rect tag.
network
microsoft CWE-119
critical
9.3
2006-01-10 CVE-2006-0002 Remote Code Execution vulnerability in Microsoft Outlook / Microsoft Exchange TNEF Decoding
Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.
network
low complexity
microsoft
7.5
2005-05-02 CVE-2005-1052 Unspecified vulnerability in Microsoft Outlook and Outlook web Access
Microsoft Outlook 2003 and Outlook Web Access (OWA) 2003 do not properly display comma separated addresses in the From field in an e-mail message, which could allow remote attackers to spoof e-mail addresses.
network
low complexity
microsoft
5.0
2004-12-31 CVE-2004-2482 Unspecified vulnerability in Microsoft Outlook 2000/2003
Microsoft Outlook 2000 and 2003, when configured to use Microsoft Word 2000 or 2003 as the e-mail editor and when forwarding e-mail, does not properly handle an opening OBJECT tag that does not have a closing OBJECT tag, which causes Outlook to automatically download the URI in the data property of the OBJECT tag and might allow remote attackers to execute arbitrary code.
network
low complexity
microsoft
5.0
2004-11-23 CVE-2004-0284 Unspecified vulnerability in Microsoft IE, Internet Explorer and Outlook
Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%00) after the host name.
network
low complexity
microsoft
5.0
2004-09-28 CVE-2004-0200 Unspecified vulnerability in Microsoft products
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.
network
microsoft
critical
9.3