49 results (0.005 seconds)

CVSS: 7.8EPSS: 0%CPEs: 5EXPL: 0

09 Jul 2024 — Microsoft Outlook Spoofing Vulnerability Vulnerabilidad de suplantación de Microsoft Outlook • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38020 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 9.0EPSS: 17%CPEs: 8EXPL: 0

11 Jun 2024 — Microsoft Outlook Remote Code Execution Vulnerability Vulnerabilidad de ejecución remota de código de Microsoft Outlook • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30103 • CWE-184: Incomplete List of Disallowed Inputs •

CVSS: 9.0EPSS: 47%CPEs: 4EXPL: 1

13 Feb 2024 — Microsoft Outlook Remote Code Execution Vulnerability Vulnerabilidad de ejecución remota de código de Microsoft Outlook • https://github.com/d0rb/CVE-2024-21378 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 7.8EPSS: 3%CPEs: 8EXPL: 0

12 Sep 2023 — Microsoft Outlook Information Disclosure Vulnerability Vulnerabilidad de Divulgación de Información de Microsoft Outlook • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36763 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 7.8EPSS: 4%CPEs: 6EXPL: 0

08 Aug 2023 — Microsoft Outlook Spoofing Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36893 • CWE-20: Improper Input Validation •

CVSS: 10.0EPSS: 24%CPEs: 6EXPL: 0

11 Jul 2023 — Microsoft Outlook Security Feature Bypass Vulnerability Microsoft Outlook contains a security feature bypass vulnerability that allows an attacker to bypass the Microsoft Outlook Security Notice prompt. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35311 • CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition •

CVSS: 10.0EPSS: 10%CPEs: 9EXPL: 2

13 Jun 2023 — Microsoft Outlook Remote Code Execution Vulnerability Microsoft Outlook suffers from a remote code execution via a maliciously crafted word file. • https://packetstorm.news/files/id/173361 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 10.0EPSS: 93%CPEs: 6EXPL: 32

14 Mar 2023 — Microsoft Outlook Elevation of Privilege Vulnerability Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user. • https://packetstorm.news/files/id/171376 • CWE-20: Improper Input Validation CWE-294: Authentication Bypass by Capture-replay •

CVSS: 7.8EPSS: 6%CPEs: 6EXPL: 0

18 Aug 2022 — Microsoft Outlook Denial of Service Vulnerability Vulnerabilidad de denegación de servicios encontrada en Microsoft Outlook. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Microsoft Outlook. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of MIME headers. Crafted MIME headers within an email message can cause Outlook to release an invalid pointer. An attacker can leverage this vulnerab... • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-35742 •

CVSS: 7.8EPSS: 0%CPEs: 5EXPL: 0

08 Jun 2021 — Microsoft Outlook Remote Code Execution Vulnerability Una vulnerabilidad de Ejecución de Código Remota en Microsoft Outlook • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-31949 • CWE-94: Improper Control of Generation of Code ('Code Injection') •