← Back

Outlook Express

outlook_express

Vendor: Microsoft • 45 CVEs

CVEs (45)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
4Ie
Internet ExplorerOutlook+1 more
Apr 16, 2026
Nov 11, 1999
N/A· v4
N/A· v3
5.1 MEDIUM· v2
A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an attachment and an embedded script in an HTML mail, aka the "Active Setup Control" vulnerability.
2Microsoft
Qualcomm
4Eudora
FrontpageInternet Explorer+1 more
Apr 16, 2026
Aug 27, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service...Show more
Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as text inputs in a table cell.Show less
1Microsoft
2Outlook
Outlook Express
Apr 16, 2026
Jun 25, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft Outlook client allows remote attackers to cause a denial of service by sending multiple email messages with the same X-UIDL headers, which causes Outlook to hang.
1Microsoft
1Outlook Express
Apr 16, 2026
May 11, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft Outlook Express before 4.72.3612.1700 allows a malicious user to send a message that contains a .., which can inadvertently cause Outlook to re-enter POP3 command mode and cause the POP3 session to hang.
1Microsoft
3Internet Explorer
Outlook ExpressWindows Explorer
Apr 16, 2026
Nov 1, 1997
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol.