Outlook Express

Vendor:

First CVE: Nov 1, 1997 · Active for 28 years

45
Total CVEs
More Total CVEs than 97% of tracked products
3.8
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Outlook Express over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 1, 1997
28 years ago
Most Recent CVE
Aug 27, 2010
5,812 days ago

CVE Severity & Scoring

Outlook Express45 CVEs
All CVEs352,713 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network1 (2.2%)
Unknown44 (97.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (2.2%)
High0 (0.0%)
Unknown44 (97.8%)
User Interaction
None0 (0.0%)
Unknown44 (97.8%)
Required1 (2.2%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (2.2%)
Unknown44 (97.8%)

Top CVEs

Signals from CVEs in this product scope (45 CVEs).

45 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows remote malicious NNTP servers to execute arbitrary code via a L
Jun 14, 20057.577NOYES
The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as d
May 4, 200410.073NOYES
Heap-based buffer overflow in Microsoft Outlook Express 6 and earlier, and Windows Mail for Vista, allows remote Network News Transfer Protocol (NNTP) servers to execute arbitrary
Oct 9, 20079.354NONO
Integer overflow in inetcomm.dll in Microsoft Outlook Express 5.5 SP2, 6, and 6 SP1; Windows Live Mail on Windows XP SP2 and SP3, Windows Vista SP1 and SP2, Windows Server 2008 Gol
May 12, 20109.350NOYES
Untrusted search path vulnerability in wab.exe 6.00.2900.5512 in Windows Address Book in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windo
Aug 27, 20109.348NOYES
Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute scripts when Active Scripting is disabled by including the scripts in XML styleshe
Apr 20, 20017.544NOYES
A component in Microsoft Outlook Express 6 allows remote attackers to bypass domain restrictions and obtain sensitive information via redirections with the mhtml: URI handler, as o
May 1, 20064.340NOYES
Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs via an HTML email with the CODEBA
Dec 31, 20038.839NOYES
Buffer overflow in the S/MIME Parsing capability in Microsoft Outlook Express 5.5 and 6.0 allows remote attackers to execute arbitrary code via a digitally signed email with a long
Oct 28, 20027.538NOYES
Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the "Automatically put people I reply to in my address book" option enabled, do not notify the user when
Jun 5, 20017.538NOYES

Exploit Exposure

Signals from CVEs in this product scope (45 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.2% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
19 CVEs
42.2% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (45 CVEs).

Media Mentions

Signals from CVEs in this product scope (45 CVEs).

Top CNAs Publishing CVEs For Outlook Express

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.00.2900.551226.815.5%01
6.00.2800.110625.04.7%00
6.0226.625.9%08
5.5136.728.3%09
5.0.317.517.4%00
5.0.226.318.6%00
5.0.165.820.9%03
5.0145.918.0%09
4.72.3612.170025.06.9%01
4.72.361226.318.5%02
4.72.3120.055.513.6%04
4.72.2106.425.06.9%01
4.72.210626.318.5%02
4.517.519.7%01
4.27.3110.135.010.4%02
4.27.311026.318.5%02
4.0155.521.0%03
4.065.820.8%04