Vulnerabilities > Microsoft > Outlook > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2002-12-31 | CVE-2002-2101 | Unspecified vulnerability in Microsoft Outlook 2002 Microsoft Outlook 2002 allows remote attackers to execute arbitrary JavaScript code, even when scripting is disabled, via an "about:" or "javascript:" URI in the href attribute of an "a" tag. | 7.5 |
2002-05-16 | CVE-2002-1056 | Unspecified vulnerability in Microsoft Outlook and Word Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to. | 7.5 |
2001-05-03 | CVE-2001-0145 | Unspecified vulnerability in Microsoft Outlook and Outlook Express Buffer overflow in VCard handler in Outlook 2000 and 98, and Outlook Express 5.x, allows an attacker to execute arbitrary commands via a malformed vCard birthday field. | 7.5 |
2000-07-20 | CVE-2000-0621 | Unspecified vulnerability in Microsoft Outlook and Outlook Express Microsoft Outlook 98 and 2000, and Outlook Express 4.0x and 5.0x, allow remote attackers to read files on the client's system via a malformed HTML message that stores files outside of the cache, aka the "Cache Bypass" vulnerability. | 7.5 |
2000-05-11 | CVE-2000-0419 | Unspecified vulnerability in Microsoft products The Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers to conduct unauthorized activities via the "Show Me" function in Office Help, aka the "Office 2000 UA Control" vulnerability. | 7.5 |
1997-01-01 | CVE-1999-0519 | Unspecified vulnerability in Microsoft products A NETBIOS/SMB share password is the default, null, or missing. | 7.5 |