Show filters
47 Total Results
Displaying 11-20 of 47
Sort by:
Attacker Value
Unknown

CVE-2006-2111

Disclosure Date: May 01, 2006 (last updated October 04, 2023)
A component in Microsoft Outlook Express 6 allows remote attackers to bypass domain restrictions and obtain sensitive information via redirections with the mhtml: URI handler, as originally reported for Internet Explorer 6 and 7, aka "URL Redirect Cross Domain Information Disclosure Vulnerability."
0
Attacker Value
Unknown

CVE-2006-0014

Disclosure Date: April 12, 2006 (last updated October 04, 2023)
Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode strings" and modified length values.
0
Attacker Value
Unknown

CVE-2005-4840

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
The Outlook Express Address Book control, when using Internet Explorer 6, allows remote attackers to cause a denial of service (NULL dereference and browser crash) by creating the OutlookExpress.AddressBook COM object, which is not intended for use within Internet Explorer.
0
Attacker Value
Unknown

CVE-2005-2226

Disclosure Date: July 12, 2005 (last updated February 22, 2025)
Microsoft Outlook Express 6.0 leaks the default news server account when a user responds to a "watched" conversation thread, which could allow remote attackers to obtain sensitive information.
0
Attacker Value
Unknown

CVE-2005-1213

Disclosure Date: June 14, 2005 (last updated February 22, 2025)
Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows remote malicious NNTP servers to execute arbitrary code via a LIST response with a long second field.
0
Attacker Value
Unknown

CVE-2004-2694

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Microsoft Outlook Express 6.0 allows remote attackers to bypass intended access restrictions, load content from arbitrary sources into the Outlook context, and facilitate phishing attacks via a "BASE HREF" with the target set to "_top".
0
Attacker Value
Unknown

CVE-2004-2137

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Outlook Express 6.0, when sending multipart e-mail messages using the "Break apart messages larger than" setting, leaks the BCC recipients of the message to the addresses listed in the To and CC fields, which may allow remote attackers to obtain sensitive information.
0
Attacker Value
Unknown

CVE-2004-0526

Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Unknown versions of Internet Explorer and Outlook allow remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.
0
Attacker Value
Unknown

CVE-2004-0215

Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header.
0
Attacker Value
Unknown

CVE-2004-0380

Disclosure Date: May 04, 2004 (last updated February 22, 2025)
The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability."
0