Show filters
183 Total Results
Displaying 131-140 of 183
Sort by:
Attacker Value
Unknown
CVE-2004-0501
Disclosure Date: August 18, 2004 (last updated February 22, 2025)
Outlook 2003 allows remote attackers to bypass intended access restrictions and cause Outlook to request a URL from a remote site via an HTML e-mail message containing a Vector Markup Language (VML) entity whose src parameter points to the remote site, which could allow remote attackers to know when a message has been read, verify valid e-mail addresses, and possibly leak other information.
0
Attacker Value
Unknown
CVE-2004-0503
Disclosure Date: August 18, 2004 (last updated February 22, 2025)
Microsoft Outlook 2003 allows remote attackers to bypass the default zone restrictions and execute script within media files via a Rich Text Format (RTF) message containing an OLE object for the Windows Media Player, which bypasses Media Player's setting to disallow scripting and may lead to unprompted installation of an executable when exploited in conjunction with predictable-file-location exposures such as CVE-2004-0502.
0
Attacker Value
Unknown
CVE-2004-0204
Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete arbitrary files via ".." sequences in the dynamicimag argument to crystalimagehandler.aspx.
0
Attacker Value
Unknown
CVE-2004-0526
Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Unknown versions of Internet Explorer and Outlook allow remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.
0
Attacker Value
Unknown
CVE-2004-0215
Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header.
0
Attacker Value
Unknown
CVE-2003-1048
Disclosure Date: July 27, 2004 (last updated February 22, 2025)
Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.
0
Attacker Value
Unknown
CVE-2004-0380
Disclosure Date: May 04, 2004 (last updated February 22, 2025)
The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability."
0
Attacker Value
Unknown
CVE-2004-0121
Disclosure Date: April 15, 2004 (last updated February 22, 2025)
Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.
0
Attacker Value
Unknown
CVE-2003-1378
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs via an HTML email with the CODEBASE parameter set to the program, a vulnerability similar to CAN-2002-0077.
0
Attacker Value
Unknown
CVE-2003-0301
Disclosure Date: June 16, 2003 (last updated February 22, 2025)
The IMAP Client for Outlook Express 6.00.2800.1106 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors.
0