cbcvebase.

Microsoft Windows Server 2008 vulnerabilities

3,037 known vulnerabilities affecting microsoft/windows_server_2008.

Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39

Vulnerabilities

Page 116 of 152
CVE-2025-49681P3MEDIUMCVSS 6.5vr22025-07-08
CVE-2025-49681 [MEDIUM] CWE-125 CVE-2025-49681: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2019-1099P3MEDIUMCVSS 6.5vr22019-07-15
CVE-2019-1099 [MEDIUM] CVE-2019-1099: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1094, CVE-2019-1095, CVE-2019-1098, CVE-2019-1100, CVE-2019-1101, CVE-2019-1116.
nvd
CVE-2019-1094P3MEDIUMCVSS 6.5vr22019-07-15
CVE-2019-1094 [MEDIUM] CWE-200 CVE-2019-1094: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1095, CVE-2019-1098, CVE-2019-1099, CVE-2019-1100, CVE-2019-1101, CVE-2019-1116.
nvd
CVE-2019-1116P3MEDIUMCVSS 6.5vr22019-07-15
CVE-2019-1116 [MEDIUM] CVE-2019-1116: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1094, CVE-2019-1095, CVE-2019-1098, CVE-2019-1099, CVE-2019-1100, CVE-2019-1101.
nvd
CVE-2019-1101P3MEDIUMCVSS 6.5vr22019-07-15
CVE-2019-1101 [MEDIUM] CVE-2019-1101: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1094, CVE-2019-1095, CVE-2019-1098, CVE-2019-1099, CVE-2019-1100, CVE-2019-1116.
nvd
CVE-2019-1098P3MEDIUMCVSS 6.5vr22019-07-15
CVE-2019-1098 [MEDIUM] CVE-2019-1098: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1094, CVE-2019-1095, CVE-2019-1099, CVE-2019-1100, CVE-2019-1101, CVE-2019-1116.
nvd
CVE-2019-1100P3MEDIUMCVSS 6.5vr22019-07-15
CVE-2019-1100 [MEDIUM] CVE-2019-1100: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1094, CVE-2019-1095, CVE-2019-1098, CVE-2019-1099, CVE-2019-1101, CVE-2019-1116.
nvd
CVE-2019-1095P3MEDIUMCVSS 6.5vr22019-07-15
CVE-2019-1095 [MEDIUM] CVE-2019-1095: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1094, CVE-2019-1098, CVE-2019-1099, CVE-2019-1100, CVE-2019-1101, CVE-2019-1116.
nvd
CVE-2017-0170P4MEDIUMCVSS 6.5vr22017-07-11
CVE-2017-0170 [MEDIUM] CWE-611 CVE-2017-0170: Windows Performance Monitor in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windo Windows Performance Monitor in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an information disclosure vulnerability due to the way it parses XML input, aka "Windows Performance Monitor Information Disclosure Vulnerabili
nvd
CVE-2017-8695P3MEDIUMCVSS 5.3vr22017-09-13
CVE-2017-8695 [MEDIUM] CWE-200 CVE-2017-8695: Windows Uniscribe in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windo Windows Uniscribe in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, 1607, 1703, and Server 2016; Office 2007 SP3; Office 2010 SP2; Word Viewer; Office for Mac 2011 and 2016; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live
nvd
CVE-2020-0853P4MEDIUMCVSS 6.5vr22020-03-12
CVE-2020-0853 [MEDIUM] CVE-2020-0853: An information disclosure vulnerability exists in Windows when the Windows Imaging Component fails t An information disclosure vulnerability exists in Windows when the Windows Imaging Component fails to properly handle objects in memory, aka 'Windows Imaging Component Information Disclosure Vulnerability'.
nvd
CVE-2015-2416P3MEDIUMCVSS 5.0vr22015-07-14
CVE-2015-2416 [MEDIUM] CWE-20 CVE-2015-2416: OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Win OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to gain privileges via crafted input, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "OLE Elevation of P
nvd
CVE-2015-2417P3MEDIUMCVSS 5.0vr22015-07-14
CVE-2015-2417 [MEDIUM] CVE-2015-2417: OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Win OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to gain privileges via crafted input, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "OLE Elevation of Privileg
nvd
CVE-2017-8534P3MEDIUMCVSS 6.5vr22017-06-15
CVE-2017-8534 [MEDIUM] CVE-2017-8534: Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gol Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, Windows Server 2016, Microsoft Office 2007 SP3, and Microsoft Office 2010 SP2 allows improper disclosure of memory contents, aka "Windows Uniscribe Information Disclosure Vulnerability". This CVE ID is uniq
nvd
CVE-2021-38665P4MEDIUMCVSS 6.5vr22021-11-10
CVE-2021-38665 [MEDIUM] CVE-2021-38665: Remote Desktop Protocol Client Information Disclosure Vulnerability Remote Desktop Protocol Client Information Disclosure Vulnerability
nvd
CVE-2019-0704P3MEDIUMCVSS 6.5vr22019-04-09
CVE-2019-0704 [MEDIUM] CVE-2019-0704: An information disclosure vulnerability exists in the way that the Windows SMB Server handles certai An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0703, CVE-2019-0821.
nvd
CVE-2019-1025P3MEDIUMCVSS 6.5vr22019-06-12
CVE-2019-1025 [MEDIUM] CVE-2019-1025: A denial of service vulnerability exists when Windows improperly handles objects in memory. An attac A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application or to convince a user to open a specif
nvd
CVE-2019-1432P3MEDIUMCVSS 6.5vr22019-11-12
CVE-2019-1432 [MEDIUM] CVE-2019-1432: An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1411.
nvd
CVE-2023-21527P3HIGHCVSS 7.5vr22023-01-10
CVE-2023-21527 [HIGH] CWE-191 CVE-2023-21527: Windows iSCSI Service Denial of Service Vulnerability Windows iSCSI Service Denial of Service Vulnerability
nvd
CVE-2023-35330P4HIGHCVSS 7.5vr22023-07-11
CVE-2023-35330 [HIGH] CWE-126 CVE-2023-35330: Windows Extended Negotiation Denial of Service Vulnerability Windows Extended Negotiation Denial of Service Vulnerability
nvd
Microsoft Windows Server 2008 vulnerabilities | cvebase