Vulnerabilities > Microsoft > Outlook > High

DATE CVE VULNERABILITY TITLE RISK
2002-12-31 CVE-2002-2101 Unspecified vulnerability in Microsoft Outlook 2002
Microsoft Outlook 2002 allows remote attackers to execute arbitrary JavaScript code, even when scripting is disabled, via an "about:" or "javascript:" URI in the href attribute of an "a" tag.
network
low complexity
microsoft
7.5
2002-05-16 CVE-2002-1056 Unspecified vulnerability in Microsoft Outlook and Word
Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to.
network
low complexity
microsoft
7.5
2001-05-03 CVE-2001-0145 Unspecified vulnerability in Microsoft Outlook and Outlook Express
Buffer overflow in VCard handler in Outlook 2000 and 98, and Outlook Express 5.x, allows an attacker to execute arbitrary commands via a malformed vCard birthday field.
network
low complexity
microsoft
7.5
2000-07-20 CVE-2000-0621 Unspecified vulnerability in Microsoft Outlook and Outlook Express
Microsoft Outlook 98 and 2000, and Outlook Express 4.0x and 5.0x, allow remote attackers to read files on the client's system via a malformed HTML message that stores files outside of the cache, aka the "Cache Bypass" vulnerability.
network
low complexity
microsoft
7.5
2000-05-11 CVE-2000-0419 Unspecified vulnerability in Microsoft products
The Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers to conduct unauthorized activities via the "Show Me" function in Office Help, aka the "Office 2000 UA Control" vulnerability.
network
low complexity
microsoft
7.5
1997-01-01 CVE-1999-0519 Unspecified vulnerability in Microsoft products
A NETBIOS/SMB share password is the default, null, or missing.
network
low complexity
microsoft
7.5