cbcvebase.

Microsoft Windows Server 2008 vulnerabilities

3,037 known vulnerabilities affecting microsoft/windows_server_2008.

Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39

Vulnerabilities

Page 112 of 152
CVE-2019-0619P3MEDIUMCVSS 6.5vr22019-03-05
CVE-2019-0619 [MEDIUM] CVE-2019-0619: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0602, CVE-2019-0615, CVE-2019-0616, CVE-2019-0660, CVE-2019-0664.
nvd
CVE-2025-58735P3HIGHCVSS 7.0vr22025-10-14
CVE-2025-58735 [HIGH] CWE-416 CVE-2025-58735: Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-58732P3HIGHCVSS 7.0vr22025-10-14
CVE-2025-58732 [HIGH] CWE-416 CVE-2025-58732: Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-53147P3HIGHCVSS 7.0vr22025-08-12
CVE-2025-53147 [HIGH] CWE-416 CVE-2025-53147: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-27474P3MEDIUMCVSS 6.5vr22025-04-08
CVE-2025-27474 [MEDIUM] CWE-908 CVE-2025-27474: Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthor Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-54093P3HIGHCVSS 7.0vr22025-09-09
CVE-2025-54093 [HIGH] CWE-367 CVE-2025-54093: Time-of-check time-of-use (toctou) race condition in Windows TCP/IP allows an authorized attacker to Time-of-check time-of-use (toctou) race condition in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-58730P3HIGHCVSS 7.0vr22025-10-14
CVE-2025-58730 [HIGH] CWE-416 CVE-2025-58730: Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-58736P3HIGHCVSS 7.0vr22025-10-14
CVE-2025-58736 [HIGH] CWE-416 CVE-2025-58736: Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-58733P3HIGHCVSS 7.0vr22025-10-14
CVE-2025-58733 [HIGH] CWE-416 CVE-2025-58733: Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
nvd
CVE-2023-28223P3MEDIUMCVSS 6.6vr22023-04-11
CVE-2023-28223 [MEDIUM] CWE-416 CVE-2023-28223: Windows Domain Name Service Remote Code Execution Vulnerability Windows Domain Name Service Remote Code Execution Vulnerability
nvd
CVE-2015-0061P4MEDIUMCVSS 4.3vr22015-02-11
CVE-2015-0061 [MEDIUM] CWE-200 CVE-2015-0061: Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly initialize memory for TIFF images, which allows remote attackers to obtain sensitive information from process memory via a crafted image file, aka "
nvd
CVE-2025-32715P3MEDIUMCVSS 6.5vr22025-06-10
CVE-2025-32715 [MEDIUM] CWE-125 CVE-2025-32715: Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2023-32043P3MEDIUMCVSS 6.8vr22023-07-11
CVE-2023-32043 [MEDIUM] CWE-327 CVE-2023-32043: Windows Remote Desktop Security Feature Bypass Vulnerability Windows Remote Desktop Security Feature Bypass Vulnerability
nvd
CVE-2025-55225P3MEDIUMCVSS 6.5vr22025-09-09
CVE-2025-55225 [MEDIUM] CWE-125 CVE-2025-55225: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2023-28308P3MEDIUMCVSS 6.6vr22023-04-11
CVE-2023-28308 [MEDIUM] CWE-416 CVE-2023-28308: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2023-28278P3MEDIUMCVSS 6.6vr22023-04-11
CVE-2023-28278 [MEDIUM] CWE-591 CVE-2023-28278: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2023-28305P3MEDIUMCVSS 6.6vr22023-04-11
CVE-2023-28305 [MEDIUM] CWE-416 CVE-2023-28305: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2023-28306P3MEDIUMCVSS 6.6vr22023-04-11
CVE-2023-28306 [MEDIUM] CWE-416 CVE-2023-28306: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2023-28307P3MEDIUMCVSS 6.6vr22023-04-11
CVE-2023-28307 [MEDIUM] CWE-416 CVE-2023-28307: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2023-28255P3MEDIUMCVSS 6.6vr22023-04-11
CVE-2023-28255 [MEDIUM] CWE-591 CVE-2023-28255: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
Microsoft Windows Server 2008 vulnerabilities | cvebase