
CVE-2000-0567 – Microsoft Outlook 97/98/2000 / Outlook Express 4.0/5.0 - GMT Field Buffer Overflow
https://notcve.org/view.php?id=CVE-2000-0567
18 Jul 2000 — Buffer overflow in Microsoft Outlook and Outlook Express allows remote attackers to execute arbitrary commands via a long Date field in an email header, aka the "Malformed E-mail Header" vulnerability. • https://www.exploit-db.com/exploits/20078 •

CVE-2000-0415
https://notcve.org/view.php?id=CVE-2000-0415
12 May 2000 — Buffer overflow in Outlook Express 4.x allows attackers to cause a denial of service via a mail or news message that has a .jpg or .bmp attachment with a long file name. • http://archives.neohapsis.com/archives/bugtraq/2000-05/0140.html •

CVE-2000-0105 – Microsoft Outlook Express 5 - JavaScript Email Access
https://notcve.org/view.php?id=CVE-2000-0105
01 Feb 2000 — Outlook Express 5.01 and Internet Explorer 5.01 allow remote attackers to view a user's email messages via a script that accesses a variable that references subsequent email messages that are read by the client. • https://www.exploit-db.com/exploits/19738 •

CVE-2000-0036
https://notcve.org/view.php?id=CVE-2000-0036
22 Dec 1999 — Outlook Express 5 for Macintosh downloads attachments to HTML mail without prompting the user, aka the "HTML Mail Attachment" vulnerability. • http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ249082 •

CVE-2000-0329 – Microsoft Internet Explorer 4.x/5 / Outlook 2000 0/98 0/Express 4.x - ActiveX '.CAB' File Execution
https://notcve.org/view.php?id=CVE-2000-0329
11 Nov 1999 — A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an attachment and an embedded script in an HTML mail, aka the "Active Setup Control" vulnerability. • https://www.exploit-db.com/exploits/19603 •

CVE-1999-1016 – Microsoft Internet Explorer 5 - HTML Form Control Denial of Service
https://notcve.org/view.php?id=CVE-1999-1016
27 Aug 1999 — Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as text inputs in a table cell. • https://www.exploit-db.com/exploits/19471 •

CVE-1999-1033 – Microsoft Outlook Express 4.27.3110/4.72.3120 - POP Denial of Service
https://notcve.org/view.php?id=CVE-1999-1033
11 May 1999 — Microsoft Outlook Express before 4.72.3612.1700 allows a malicious user to send a message that contains a .., which can inadvertently cause Outlook to re-enter POP3 command mode and cause the POP3 session to hang. • https://www.exploit-db.com/exploits/19207 •