Page 5 of 46 results (0.002 seconds)

CVSS: 6.5EPSS: 19%CPEs: 2EXPL: 0

22 Dec 1999 — Outlook Express 5 for Macintosh downloads attachments to HTML mail without prompting the user, aka the "HTML Mail Attachment" vulnerability. • http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ249082 •

CVSS: 8.8EPSS: 8%CPEs: 20EXPL: 1

11 Nov 1999 — A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an attachment and an embedded script in an HTML mail, aka the "Active Setup Control" vulnerability. • https://www.exploit-db.com/exploits/19603 •

CVSS: 7.4EPSS: 8%CPEs: 4EXPL: 2

27 Aug 1999 — Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as text inputs in a table cell. • https://www.exploit-db.com/exploits/19471 •

CVSS: 7.5EPSS: 7%CPEs: 4EXPL: 0

25 Jun 1999 — Microsoft Outlook client allows remote attackers to cause a denial of service by sending multiple email messages with the same X-UIDL headers, which causes Outlook to hang. • http://marc.info/?l=bugtraq&m=93041631215856&w=2 •

CVSS: 9.1EPSS: 8%CPEs: 3EXPL: 2

11 May 1999 — Microsoft Outlook Express before 4.72.3612.1700 allows a malicious user to send a message that contains a .., which can inadvertently cause Outlook to re-enter POP3 command mode and cause the POP3 session to hang. • https://www.exploit-db.com/exploits/19207 •

CVSS: 10.0EPSS: 17%CPEs: 3EXPL: 0

01 Nov 1997 — Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol. • https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0967 •