Show filters
183 Total Results
Displaying 11-20 of 183
Sort by:
Attacker Value
Unknown

CVE-2024-42220

Disclosure Date: December 18, 2024 (last updated December 20, 2024)
A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and then make use of the vulnerable application's permissions.
0
Attacker Value
Unknown

CVE-2024-30133

Disclosure Date: November 12, 2024 (last updated November 13, 2024)
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a control flow vulnerability. The application does not sufficiently manage its control flow during execution, creating conditions in which the control flow can be modified in unexpected ways.
0
Attacker Value
Unknown

CVE-2024-43604

Disclosure Date: October 08, 2024 (last updated October 18, 2024)
Outlook for Android Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2024-30134

Disclosure Date: September 26, 2024 (last updated September 27, 2024)
The HCL Traveler for Microsoft Outlook executable (HTMO.exe) is being flagged as potentially Malicious Software or an Unrecognized Application.
0
Attacker Value
Unknown

CVE-2024-43482

Disclosure Date: September 10, 2024 (last updated September 19, 2024)
Microsoft Outlook for iOS Information Disclosure Vulnerability
Attacker Value
Unknown

CVE-2024-38173

Disclosure Date: August 13, 2024 (last updated August 17, 2024)
Microsoft Outlook Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2024-38020

Disclosure Date: July 09, 2024 (last updated July 12, 2024)
Microsoft Outlook Spoofing Vulnerability
Attacker Value
Unknown

CVE-2024-29210

Disclosure Date: May 07, 2024 (last updated May 08, 2024)
A local privilege escalation (LPE) vulnerability has been identified in Phish Alert Button for Outlook (PAB), specifically within its configuration management functionalities. This vulnerability allows a regular user to modify the application's configuration file to redirect update checks to an arbitrary server, which can then be exploited in conjunction with CVE-2024-29209 to execute arbitrary code with elevated privileges. The issue stems from improper permission settings on the application's configuration file, which is stored in a common directory accessible to all users. This file includes critical parameters, such as the update server URL. By default, the application does not enforce adequate access controls on this file, allowing non-privileged users to modify it without administrative consent. An attacker with regular user access can alter the update server URL specified in the configuration file to point to a malicious server. When the application performs its next update c…
0
Attacker Value
Unknown

CVE-2024-29209

Disclosure Date: May 07, 2024 (last updated May 08, 2024)
A medium severity vulnerability has been identified in the update mechanism of the Phish Alert Button for Outlook, which could allow an attacker to remotely execute arbitrary code on the host machine. The vulnerability arises from the application's failure to securely verify the authenticity and integrity of the update server. The application periodically checks for updates by querying a specific URL. However, this process does not enforce strict SSL/TLS verification, nor does it validate the digital signature of the received update files. An attacker with the capability to perform DNS spoofing can exploit this weakness. By manipulating DNS responses, the attacker can redirect the application's update requests to a malicious server under their control. Once the application queries the spoofed update URL, the malicious server can respond with a crafted update package. Since the application fails to properly verify the authenticity of the update file, it will accept and execute the pa…
0
Attacker Value
Unknown

CVE-2024-20670

Disclosure Date: April 09, 2024 (last updated January 12, 2025)
Outlook for Windows Spoofing Vulnerability
0