Show filters
183 Total Results
Displaying 111-120 of 183
Sort by:
Attacker Value
Unknown

CVE-2006-1305

Disclosure Date: December 31, 2006 (last updated October 04, 2023)
Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to cause a denial of service (memory exhaustion and interrupted mail recovery) via malformed e-mail header information, possibly related to (1) long subject lines or (2) large numbers of recipients in To or CC headers.
0
Attacker Value
Unknown

CVE-2006-6659

Disclosure Date: December 20, 2006 (last updated October 04, 2023)
The Microsoft Office Outlook Recipient ActiveX control (ole32.dll) in Windows XP SP2 allows remote attackers to cause a denial of service (Internet Explorer 7 hang) via crafted HTML.
0
Attacker Value
Unknown

CVE-2006-2386

Disclosure Date: December 13, 2006 (last updated October 04, 2023)
Unspecified vulnerability in Microsoft Outlook Express 6 and earlier allows remote attackers to execute arbitrary code via a crafted contact record in a Windows Address Book (WAB) file.
0
Attacker Value
Unknown

CVE-2006-3877

Disclosure Date: October 10, 2006 (last updated October 04, 2023)
Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via an unspecified "crafted file," a different vulnerability than CVE-2006-3435, CVE-2006-4694, and CVE-2006-3876.
0
Attacker Value
Unknown

CVE-2006-4868

Disclosure Date: September 19, 2006 (last updated October 04, 2023)
Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft Outlook and Internet Explorer 6.0 on Windows XP SP2, and possibly other versions, allows remote attackers to execute arbitrary code via a Vector Markup Language (VML) file with a long fill parameter within a rect tag.
0
Attacker Value
Unknown

CVE-2006-2111

Disclosure Date: May 01, 2006 (last updated October 04, 2023)
A component in Microsoft Outlook Express 6 allows remote attackers to bypass domain restrictions and obtain sensitive information via redirections with the mhtml: URI handler, as originally reported for Internet Explorer 6 and 7, aka "URL Redirect Cross Domain Information Disclosure Vulnerability."
0
Attacker Value
Unknown

CVE-2006-2055

Disclosure Date: April 26, 2006 (last updated October 04, 2023)
Argument injection vulnerability in Microsoft Outlook 2003 SP1 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment. NOTE: it is not clear whether this issue is implementation-specific or a problem in the Microsoft API.
0
Attacker Value
Unknown

CVE-2006-0014

Disclosure Date: April 12, 2006 (last updated October 04, 2023)
Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode strings" and modified length values.
0
Attacker Value
Unknown

CVE-2006-0002

Disclosure Date: January 10, 2006 (last updated October 04, 2023)
Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.
0
Attacker Value
Unknown

CVE-2005-4840

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
The Outlook Express Address Book control, when using Internet Explorer 6, allows remote attackers to cause a denial of service (NULL dereference and browser crash) by creating the OutlookExpress.AddressBook COM object, which is not intended for use within Internet Explorer.
0