cbcvebase.

Microsoft Windows Server 2008 vulnerabilities

3,037 known vulnerabilities affecting microsoft/windows_server_2008.

Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39

Vulnerabilities

Page 130 of 152
CVE-2022-22028P4MEDIUMCVSS 5.9vr22022-07-12
CVE-2022-22028 [MEDIUM] CVE-2022-22028: Windows Network File System Information Disclosure Vulnerability Windows Network File System Information Disclosure Vulnerability
nvd
CVE-2011-0031P4MEDIUMCVSS 4.3vr22011-02-09
CVE-2011-0031 [MEDIUM] CWE-200 CVE-2011-0031: The (1) JScript 5.8 and (2) VBScript 5.8 scripting engines in Microsoft Windows Server 2008 R2 and W The (1) JScript 5.8 and (2) VBScript 5.8 scripting engines in Microsoft Windows Server 2008 R2 and Windows 7 do not properly load decoded scripts obtained from web pages, which allows remote attackers to trigger memory corruption and consequently obtain sensitive information via a crafted web site, aka "Scripting Engines Information Disclosure Vulnera
nvd
CVE-2017-0242P4MEDIUMCVSS 5.5vr22017-05-12
CVE-2017-0242 [MEDIUM] CWE-200 CVE-2017-0242: An information disclosure vulnerability exists in the way some ActiveX objects are instantiated, aka An information disclosure vulnerability exists in the way some ActiveX objects are instantiated, aka "Microsoft ActiveX Information Disclosure Vulnerability."
nvd
CVE-2019-1470P4MEDIUMCVSS 6.0vr22019-12-10
CVE-2019-1470 [MEDIUM] CWE-20 CVE-2019-1470: An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'.
nvd
CVE-2019-1361P4MEDIUMCVSS 5.5vr22019-10-10
CVE-2019-1361 [MEDIUM] CWE-125 CVE-2019-1361: An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Information Disclosure Vulnerability'.
nvd
CVE-2026-20839P4MEDIUMCVSS 5.5vr2-sp12026-01-13
CVE-2026-20839 [MEDIUM] CWE-284 CVE-2026-20839: Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker t Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally.
nvd
CVE-2015-0080P4MEDIUMCVSS 4.3vr22015-03-11
CVE-2015-0080 [MEDIUM] CWE-200 CVE-2015-0080: Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly initialize memory for rendering of malformed PNG images, which allows remote attackers to obtain sensitive information from process memory via a cra
nvd
CVE-2017-0191P4MEDIUMCVSS 5.8vr22017-04-12
CVE-2017-0191 [MEDIUM] CVE-2017-0191: A denial of service vulnerability exists in the way that Windows 7, Windows 8.1, Windows 10, Windows A denial of service vulnerability exists in the way that Windows 7, Windows 8.1, Windows 10, Windows Server 2008 R2, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016 handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding, aka "Windows Denial of Service Vulnerabilit
nvd
CVE-2024-30037P4MEDIUMCVSS 5.5vr22024-05-14
CVE-2024-30037 [MEDIUM] CWE-125 CVE-2024-30037: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2017-0182P4MEDIUMCVSS 5.8vr22017-04-12
CVE-2017-0182 [MEDIUM] CVE-2017-0182: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE
nvd
CVE-2019-0716P4MEDIUMCVSS 5.8vr22019-08-14
CVE-2019-0716 [MEDIUM] CVE-2019-0716: A denial of service vulnerability exists when Windows improperly handles objects in memory. An attac A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerability would not allow an
nvd
CVE-2017-0183P4MEDIUMCVSS 5.8vr22017-04-12
CVE-2017-0183 [MEDIUM] CVE-2017-0183: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE
nvd
CVE-2021-33745P4MEDIUMCVSS 6.5vr22021-07-14
CVE-2021-33745 [MEDIUM] CVE-2021-33745: Windows DNS Server Denial of Service Vulnerability Windows DNS Server Denial of Service Vulnerability
nvd
CVE-2021-34499P4MEDIUMCVSS 6.5vr22021-07-14
CVE-2021-34499 [MEDIUM] CVE-2021-34499: Windows DNS Server Denial of Service Vulnerability Windows DNS Server Denial of Service Vulnerability
nvd
CVE-2017-0171P4MEDIUMCVSS 5.9vr22017-05-12
CVE-2017-0171 [MEDIUM] CWE-20 CVE-2017-0171: Windows DNS Server allows a denial of service vulnerability when Microsoft Windows Server 2008 SP2 a Windows DNS Server allows a denial of service vulnerability when Microsoft Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 Gold and R2, and Windows Server 2016 are configured to answer version queries, aka "Windows DNS Server Denial of Service Vulnerability".
nvd
CVE-2020-0730P4HIGHCVSS 7.1vr22020-02-11
CVE-2020-0730 [HIGH] CWE-59 CVE-2020-0730: An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) impro An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'.
nvd
CVE-2018-0881P4HIGHCVSS 7.0vr22018-03-14
CVE-2018-0881 [HIGH] CVE-2018-0881: The Microsoft Video Control in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1 and The Microsoft Video Control in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege due to how objects are handled in memory, aka "Microsoft Video Control Elevation of Privilege Vul
nvd
CVE-2018-8167P4HIGHCVSS 7.0vr2-sp1v32-bit Systems Service Pack 2+4 more2018-05-09
CVE-2018-8167 [HIGH] CWE-404 CVE-2018-8167: An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka "Windows Common Log File System Driver Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server
nvd
CVE-2020-0785P4HIGHCVSS 7.1vr22020-03-12
CVE-2020-0785 [HIGH] CWE-269 CVE-2020-0785: An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) impro An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'.
nvd
CVE-2022-35759P4MEDIUMCVSS 6.5vr22023-05-31
CVE-2022-35759 [MEDIUM] CVE-2022-35759: Windows Local Security Authority (LSA) Denial of Service Vulnerability Windows Local Security Authority (LSA) Denial of Service Vulnerability
nvd
Microsoft Windows Server 2008 vulnerabilities | cvebase