Outlook Express
Vendor:
First CVE: Nov 1, 1997 · Active for 28 years
45
Total CVEs
More Total CVEs than 97% of tracked products
3.8
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Outlook Express over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 1, 1997
28 years ago
Most Recent CVE
Aug 27, 2010
5,812 days ago
CVE Severity & Scoring
Outlook Express45 CVEs
58%
40%
All CVEs352,713 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network1 (2.2%)
Unknown44 (97.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (2.2%)
High0 (0.0%)
Unknown44 (97.8%)
User Interaction
None0 (0.0%)
Unknown44 (97.8%)
Required1 (2.2%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (2.2%)
Unknown44 (97.8%)
Top CVEs
Signals from CVEs in this product scope (45 CVEs).
45 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-1213HIGH Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows remote malicious NNTP servers to execute arbitrary code via a L | Jun 14, 2005 | 7.5 | 77 | NO | YES |
CVE-2004-0380HIGH The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as d | May 4, 2004 | 10.0 | 73 | NO | YES |
CVE-2007-3897HIGH Heap-based buffer overflow in Microsoft Outlook Express 6 and earlier, and Windows Mail for Vista, allows remote Network News Transfer Protocol (NNTP) servers to execute arbitrary | Oct 9, 2007 | 9.3 | 54 | NO | NO |
CVE-2010-0816HIGH Integer overflow in inetcomm.dll in Microsoft Outlook Express 5.5 SP2, 6, and 6 SP1; Windows Live Mail on Windows XP SP2 and SP3, Windows Vista SP1 and SP2, Windows Server 2008 Gol | May 12, 2010 | 9.3 | 50 | NO | YES |
CVE-2010-3147HIGH Untrusted search path vulnerability in wab.exe 6.00.2900.5512 in Windows Address Book in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windo | Aug 27, 2010 | 9.3 | 48 | NO | YES |
CVE-2001-1325HIGH Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute scripts when Active Scripting is disabled by including the scripts in XML styleshe | Apr 20, 2001 | 7.5 | 44 | NO | YES |
CVE-2006-2111MEDIUM A component in Microsoft Outlook Express 6 allows remote attackers to bypass domain restrictions and obtain sensitive information via redirections with the mhtml: URI handler, as o | May 1, 2006 | 4.3 | 40 | NO | YES |
CVE-2003-1378HIGH Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs via an HTML email with the CODEBA | Dec 31, 2003 | 8.8 | 39 | NO | YES |
CVE-2002-1179HIGH Buffer overflow in the S/MIME Parsing capability in Microsoft Outlook Express 5.5 and 6.0 allows remote attackers to execute arbitrary code via a digitally signed email with a long | Oct 28, 2002 | 7.5 | 38 | NO | YES |
CVE-2001-1088HIGH Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the "Automatically put people I reply to in my address book" option enabled, do not notify the user when | Jun 5, 2001 | 7.5 | 38 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (45 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.2% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
19 CVEs
42.2% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (45 CVEs).
Media Mentions
Signals from CVEs in this product scope (45 CVEs).
Top CNAs Publishing CVEs For Outlook Express
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.00.2900.5512 | 2 | 6.8 | 15.5% | 0 | 1 |
| 6.00.2800.1106 | 2 | 5.0 | 4.7% | 0 | 0 |
| 6.0 | 22 | 6.6 | 25.9% | 0 | 8 |
| 5.5 | 13 | 6.7 | 28.3% | 0 | 9 |
| 5.0.3 | 1 | 7.5 | 17.4% | 0 | 0 |
| 5.0.2 | 2 | 6.3 | 18.6% | 0 | 0 |
| 5.0.1 | 6 | 5.8 | 20.9% | 0 | 3 |
| 5.0 | 14 | 5.9 | 18.0% | 0 | 9 |
| 4.72.3612.1700 | 2 | 5.0 | 6.9% | 0 | 1 |
| 4.72.3612 | 2 | 6.3 | 18.5% | 0 | 2 |
| 4.72.3120.0 | 5 | 5.5 | 13.6% | 0 | 4 |
| 4.72.2106.4 | 2 | 5.0 | 6.9% | 0 | 1 |
| 4.72.2106 | 2 | 6.3 | 18.5% | 0 | 2 |
| 4.5 | 1 | 7.5 | 19.7% | 0 | 1 |
| 4.27.3110.1 | 3 | 5.0 | 10.4% | 0 | 2 |
| 4.27.3110 | 2 | 6.3 | 18.5% | 0 | 2 |
| 4.01 | 5 | 5.5 | 21.0% | 0 | 3 |
| 4.0 | 6 | 5.8 | 20.8% | 0 | 4 |