← Vulnerability feed

Vulnerability record · CVE-2006-0014 · published 12 April 2006

CVE-2006-0014: Microsoft outlook express vulnerability

Microsoft · Outlook Express

Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode strings" and modified length values.

5.1 CVSS 2.0 Medium EPSS 24% · top 2.2%
5.1CVSS 2.0 base score
24%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
34References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode strings" and modified length values.

AV:N/AC:H/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045003.html
http://secunia.com/advisories/19617 PatchVendor Advisory
http://securityreason.com/securityalert/691
http://securitytracker.com/id?1015898
http://www.securityfocus.com/archive/1/430645/100/0/threaded
http://www.securityfocus.com/bid/17459
http://www.vupen.com/english/advisories/2006/1321
http://www.zerodayinitiative.com/advisories/ZDI-06-007.html Vendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-016
https://exchange.xforce.ibmcloud.com/vulnerabilities/25535
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1611
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1682
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1769
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1771
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1780
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1791
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A812
http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045003.html
http://secunia.com/advisories/19617 PatchVendor Advisory
http://securityreason.com/securityalert/691
http://securitytracker.com/id?1015898
http://www.securityfocus.com/archive/1/430645/100/0/threaded
http://www.securityfocus.com/bid/17459
http://www.vupen.com/english/advisories/2006/1321
http://www.zerodayinitiative.com/advisories/ZDI-06-007.html Vendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-016
https://exchange.xforce.ibmcloud.com/vulnerabilities/25535
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1611
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1682
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1769
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1771
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1780
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1791
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A812

Track CVE-2006-0014 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-0380Outlook Express MHTML handler domain bypass leads to code executionThe MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through 6 SP1 fails to enforce domain restrictions, letting remote attackers bypass s…EPSS 63%analysed10.0CVE-1999-0967Microsoft internet explorer vulnerabilityBuffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol.EPSS 6.9%9.3CVE-2010-3147Microsoft outlook express vulnerabilityUntrusted search path vulnerability in wab.exe 6.00.2900.5512 in Windows Address Book in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, W…EPSS 19%9.3CVE-2010-0816Microsoft outlook express vulnerabilityInteger overflow in inetcomm.dll in Microsoft Outlook Express 5.5 SP2, 6, and 6 SP1; Windows Live Mail on Windows XP SP2 and SP3, Windows Vista SP1 a…EPSS 20%9.3CVE-2007-3897Microsoft Outlook Express and Windows Mail NNTP heap buffer overflowOutlook Express 6 and earlier, plus Windows Mail on Vista, contain a heap-based buffer overflow triggered by long responses from an NNTP news server.…EPSS 55%analysed8.8CVE-2007-4040Microsoft outlook cross-site scripting vulnerabilityArgument injection vulnerability involving Microsoft Outlook and Outlook Express, when certain URIs are registered, allows remote attackers to conduc…EPSS 13%8.8CVE-2003-1378Microsoft outlook permissions and access controls vulnerabilityMicrosoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs vi…EPSS 16%7.5CVE-2005-1213Microsoft Outlook Express news reader stack buffer overflow via NNTP LIST responseThe news reader component of Microsoft Outlook Express (MSOE.DLL) contains a stack-based buffer overflow triggered by a long second field in an NNTP …EPSS 74%analysed

Source: NIST National Vulnerability Database (record CVE-2006-0014), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.