Secunia Logo  


Secunia PSI WorldMap
 
Vulnerability Report: Microsoft Outlook Express 6
This vulnerability report for Microsoft Outlook Express 6 contains a complete overview of all Secunia advisories affecting it. You can use this vulnerability report to ensure that you are aware of all vulnerabilities, both patched and unpatched, affecting this product allowing you to take the necessary precautions.

If you have information about a new or an existing vulnerability in Microsoft Outlook Express 6 then you are more than welcome to contact us.


Table of Contents

1. Product Summary Only

2. Secunia Advisory Statistics (All time)
2.1. Statistics for 2009
2.2. Statistics for 2008
2.3. Statistics for 2007
2.4. Statistics for 2006
2.5. Statistics for 2005
2.6. Statistics for 2004
2.7. Statistics for 2003

3. List of Secunia Advisories (All time)
3.1. List for 2009
3.2. List for 2008
3.3. List for 2007
3.4. List for 2006
3.5. List for 2005
3.6. List for 2004
3.7. List for 2003

4. Send Feedback
 
Vendor, Links, and Unpatched Vulnerabilities

Vendor Microsoft

Product Link View Here (Link to external site)

Affected By 26 Secunia advisories
14 Vulnerabilities

Monitor Product Receive alerts for this product

Unpatched 23% (6 of 26 Secunia advisories)

Most Critical Unpatched
The most severe unpatched Secunia advisory affecting Microsoft Outlook Express 6, with all vendor patches applied, is rated Moderately critical .




26 Secunia Advisories in 2003-2009
Secunia has issued a total of 26 Secunia advisories in 2003-2009 for Microsoft Outlook Express 6. Currently, 23% (6 out of 26) are marked as unpatched with the most severe being rated Moderately critical

More information about the specific Secunia advisories affecting Microsoft Outlook Express 6 can be found below. Each Secunia advisory is enclosed by a box highlighted with a color representing its current patch status. You can read the complete Secunia advisories for thorough descriptions of the issues covered and for solution suggestions by clicking either the Secunia advisory title or the "Read More" links available for each Secunia advisory.



Microsoft Windows Various Components ATL Vulnerabilities
Vendor Patch. Secunia Advisory 1 of 1 in 2009. 8,250 views.
Release Date:
2009-08-11
Secunia Advisory ID:
SA36187
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
System access
Where:
From remote
Short Description:
Multiple vulnerabilities have been reported in various Windows components, which can be exploited by malicious people to bypass security features or compromise a user's system. [Read More]


Microsoft Windows NNTP Response Handling Buffer Overflow
Vendor Patch. Secunia Advisory 1 of 2 in 2007. 14,112 views.
Release Date:
2007-10-09
Secunia Advisory ID:
SA27112
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
VeriSign iDefense Labs has reported a vulnerability in Microsoft Windows, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Outlook Express and Windows Mail Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 2 of 2 in 2007. 22,219 views.
Release Date:
2007-06-12
Secunia Advisory ID:
SA25639
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
Exposure of sensitive information
System access
Where:
From remote
Short Description:
Some vulnerabilities have been reported in Microsoft Outlook Express and Windows Mail, which can be exploited by malicious people to disclose sensitive information and compromise a user's system. [Read More]


Outlook Express Address Book Contact Record Vulnerability
Vendor Patch. Secunia Advisory 1 of 3 in 2006. 13,245 views.
Release Date:
2006-12-12
Secunia Advisory ID:
SA23311
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Outlook Express, which can be exploited by malicious people to compromise a user's system. [Read More]


Internet Explorer "mhtml:" Redirection Disclosure of Sensitive Information
Vendor Patch. Secunia Advisory 2 of 3 in 2006. 112,470 views.
Release Date:
2006-04-27
Secunia Advisory ID:
SA19738
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of sensitive information
Where:
From remote
Short Description:
codedreamer has discovered a vulnerability in Internet Explorer and Outlook Express, which can be exploited by malicious people to disclose potentially sensitive information. [Read More]


Outlook Express Windows Address Book File Vulnerability
Vendor Patch. Secunia Advisory 3 of 3 in 2006. 18,253 views.
Release Date:
2006-04-11
Secunia Advisory ID:
SA19617
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Outlook Express, which can be exploited by malicious people to compromise a user's system. [Read More]


Microsoft Outlook Express News Reading Buffer Overflow
Vendor Patch. Secunia Advisory 1 of 2 in 2005. 15,013 views.
Release Date:
2005-06-14
Secunia Advisory ID:
SA15695
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Microsoft Outlook Express, which can be exploited by malicious people to compromise a user's system. [Read More]


Internet Explorer/Outlook Express Status Bar Spoofing
Unpatched. Secunia Advisory 2 of 2 in 2005. 26,698 views.
Release Date:
2005-02-17
Secunia Advisory ID:
SA14304
Solution Status:
Unpatched
Criticality:
Impact:
Security Bypass
Where:
From remote
Short Description:
bitlance winter has discovered a weakness in Internet Explorer/Outlook Express, which can be exploited by malicious people to trick users into visiting a malicious web site by obfuscating URLs. [Read More]


Internet Explorer/Outlook Express Restricted Zone Status Bar Spoofing
Partial Fix. Secunia Advisory 1 of 6 in 2004. 32,507 views.
Release Date:
2004-10-29
Secunia Advisory ID:
SA13015
Solution Status:
Partial Fix
Criticality:
Impact:
Security Bypass
Where:
From remote
Short Description:
Benjamin Tobias Franz has discovered a weakness in Internet Explorer, which can be exploited by malicious people to trick users into visiting a malicious website by obfuscating URLs. [Read More]


Microsoft Outlook Express "BCC:" Recipient Disclosure Weakness
Vendor Patch. Secunia Advisory 2 of 6 in 2004. 30,484 views.
Release Date:
2004-08-25
Secunia Advisory ID:
SA12376
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of sensitive information
Where:
From remote
Short Description:
Juha-Matti Laurio has reported a weakness in Outlook Express, which may disclose email addresses in "BCC:" fields to other recipients. [Read More]


Microsoft Outlook Express Header Validation Denial of Service Weakness
Vendor Patch. Secunia Advisory 3 of 6 in 2004. 12,079 views.
Release Date:
2004-07-13
Secunia Advisory ID:
SA12038
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
A weakness has been discovered in Microsoft Outlook Express 6, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Microsoft Outlook Express Loading of Arbitrary Web Content
Unpatched. Secunia Advisory 4 of 6 in 2004. 11,549 views.
Release Date:
2004-05-14
Secunia Advisory ID:
SA11607
Solution Status:
Unpatched
Criticality:
Impact:
Security Bypass
Where:
From remote
Short Description:
http-equiv has reported a vulnerability in Microsoft Outlook Express, allowing malicious people (e.g. spammers and phishers) to load arbitrary content into the email client. [Read More]


Microsoft Outlook Express MHTML URL Processing Vulnerability
Vendor Patch. Secunia Advisory 5 of 6 in 2004. 44,417 views.
Release Date:
2004-04-13
Secunia Advisory ID:
SA11067
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been discovered in Outlook Express, which can be exploited by malicious people to compromise a user's system via websites or HTML emails. [Read More]


Internet Explorer/Outlook Express Restricted Zone Status Bar Spoofing
Unpatched. Secunia Advisory 6 of 6 in 2004. 55,017 views.
Release Date:
2004-04-01
Secunia Advisory ID:
SA11273
Solution Status:
Unpatched
Criticality:
Impact:
Security Bypass
Where:
From remote
Short Description:
http-equiv has discovered a weakness in Internet Explorer, which potentially can be exploited by malicious people to trick users into visiting a malicious website. [Read More]


Outlook Express File Download Security Restriction Bypass
Vendor Patch. Secunia Advisory 1 of 4 in 2003. 11,804 views.
Release Date:
2003-05-26
Secunia Advisory ID:
SA8841
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
Where:
From remote
Short Description:
A vulnerability has been identified in Outlook Express, which can be exploited to bypass the file download security restriction. [Read More]


Multiple IMAP Clients System Access Vulnerabilities
Vendor Patch. Secunia Advisory 2 of 4 in 2003. 15,347 views.
Release Date:
2003-05-20
Secunia Advisory ID:
SA8810
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From remote
Short Description:
Two different vulnerabilities have been identified in multiple IMAP clients. On some systems it could be exploited to gain control of the client system. [Read More]


Outlook Express MHTML URL Handler Vulnerability
Vendor Patch. Secunia Advisory 3 of 4 in 2003. 8,480 views.
Release Date:
2003-04-23
Secunia Advisory ID:
SA8648
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of system information
Exposure of sensitive information
System access
Where:
From remote
Short Description:
Microsoft has issued a patch for an older vulnerability in Outlook Express, which can be exploited by malicious people to perform certain actions on a user's system. [Read More]


Microsoft Outlook vulnerability may resurface
Unpatched. Secunia Advisory 4 of 4 in 2003. 8,780 views.
Release Date:
2003-02-25
Secunia Advisory ID:
SA8147
Solution Status:
Unpatched
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Microsoft issued MS02-015 last year to fix the codebase localPath vulnerability, this however was done in a flawed way, so that it still could be exploited in Internet Explorer in the "Local Zone" context. [Read More]


Microsoft vulnerabilities not fixed
Vendor Patch. Secunia Advisory 1 of 8 in 2002. 18,525 views.
Release Date:
2002-11-22
Secunia Advisory ID:
SA7579
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Microsoft issued two advisories on 20th November 2002. It appears however that the vulnerabilities STILL exist to a certain extent. [Read More]


Microsoft vulnerabilities in Internet Explorer, Outlook, Outlook Express and Internet Information Server (IIS)
Vendor Patch. Secunia Advisory 2 of 8 in 2002. 21,778 views.
Release Date:
2002-11-20
Secunia Advisory ID:
SA7567
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Remote Data Services (RDS) which is part of Microsoft Data Access Components (MDAC) contains a buffer overflow allowing attackers to run arbitrary code. [Read More]


Microsoft Outlook Express Fails to Expunge Deleted Emails
Unpatched. Secunia Advisory 3 of 8 in 2002. 11,561 views.
Release Date:
2002-10-30
Secunia Advisory ID:
SA7414
Solution Status:
Unpatched
Criticality:
Impact:
Exposure of sensitive information
Where:
Local system
Short Description:
A security issue has been reported in Microsoft Outlook Express 6, allowing malicious local users to view deleted emails. [Read More]


Microsoft Outlook Express S/MIME buffer overrun
Vendor Patch. Secunia Advisory 4 of 8 in 2002. 5,615 views.
Release Date:
2002-10-10
Secunia Advisory ID:
SA7272
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Microsoft OutLook Express suffers a vulnerability allowing attackers to construct malicious S/MIME e-mails that may execute arbitrary code when viewed. [Read More]


Fragmented email may pass AntiVirus gateways
Partial Fix. Secunia Advisory 5 of 8 in 2002. 8,484 views.
Release Date:
2002-09-12
Secunia Advisory ID:
SA7103
Solution Status:
Partial Fix
Criticality:
Impact:
Security Bypass
Where:
From remote
Short Description:
Using Outlook and Outlook Express, it is possible to send and receive message/partial emails, this means that an email can be split into multiple parts when sent and reassembled when received again. [Read More]


Denial of Service vulnerability in Outlook Express
Unpatched. Secunia Advisory 6 of 8 in 2002. 4,507 views.
Release Date:
2002-09-10
Secunia Advisory ID:
SA7086
Solution Status:
Unpatched
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
It is possible to crash Outlook Express by sending an html email with a "a href" link that is longer than 4095 characters. [Read More]


Microsoft Java Implementation Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 7 of 8 in 2002. 13,409 views.
Release Date:
2002-09-09
Secunia Advisory ID:
SA7082
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Jouko Pynnonen has reported multiple vulnerabilities in Microsoft's Java implementation, which affects all versions of Internet Explorer, Outlook Express, and Outlook. [Read More]


Internet Explorer Cross Frame Scripting
Vendor Patch. Secunia Advisory 8 of 8 in 2002. 14,382 views.
Release Date:
2002-09-09
Secunia Advisory ID:
SA7084
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Internet Explorer versions 5.5 and 6.0 are vulnerable to a Cross Frame Scripting attack, which may allow execution of arbitrary code. [Read More]