cbcvebase.

Microsoft Windows Server 2008 vulnerabilities

3,037 known vulnerabilities affecting microsoft/windows_server_2008.

Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39

Vulnerabilities

Page 132 of 152
CVE-2019-0968P4MEDIUMCVSS 5.5vr22019-06-12
CVE-2019-0968 [MEDIUM] CVE-2019-0968: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a spe
nvd
CVE-2023-20569P4MEDIUMCVSS 4.7vr22023-08-08
CVE-2023-20569 [MEDIUM] CWE-203 CVE-2023-20569: A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the retur A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure.
nvd
CVE-2019-1013P4MEDIUMCVSS 4.7vr22019-06-12
CVE-2019-1013 [MEDIUM] CWE-200 CVE-2019-1013: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to op
nvd
CVE-2017-8688P4MEDIUMCVSS 5.5vr22017-09-13
CVE-2017-8688 [MEDIUM] CVE-2017-8688: Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Se Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows information disclosure by the way it discloses kernel memory addresses, aka "Windows GDI+ Information Disclosure Vulnerability". This CVE ID is unique
nvd
CVE-2019-1053P4MEDIUMCVSS 6.3vr22019-06-12
CVE-2019-1053 [MEDIUM] CWE-59 CVE-2019-1053: An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder short An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder shortcuts. An attacker who successfully exploited the vulnerability could elevate privileges by escaping a sandbox. To exploit this vulnerability, an attacker would require unprivileged execution on the victim system. The security update addresses the vulnera
nvd
CVE-2020-16914P4MEDIUMCVSS 5.5vr22020-10-16
CVE-2020-16914 [MEDIUM] CVE-2020-16914: <p>An information disclosure vulnerability exists in the way that the Windows Graphics Device Interf An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface Plus (GDI+) handles objects in memory, allowing an attacker to retrieve information from a targeted system. By itself, the information disclosure does not allow arbitrary code execution; however, it could allow arbitrary code to be run if the attacker uses i
nvd
CVE-2025-29974P4MEDIUMCVSS 5.7vr22025-05-13
CVE-2025-29974 [MEDIUM] CWE-125 CVE-2025-29974: Integer underflow (wrap or wraparound) in Windows Kernel allows an unauthorized attacker to disclose Integer underflow (wrap or wraparound) in Windows Kernel allows an unauthorized attacker to disclose information over an adjacent network.
nvd
CVE-2020-0946P4MEDIUMCVSS 5.5vr22020-04-15
CVE-2020-0946 [MEDIUM] CVE-2020-0946: An information disclosure vulnerability exists when Media Foundation improperly handles objects in m An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory, aka 'Media Foundation Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0937, CVE-2020-0939, CVE-2020-0945, CVE-2020-0947.
nvd
CVE-2025-59513P4MEDIUMCVSS 5.5vr22025-11-11
CVE-2025-59513 [MEDIUM] CWE-125 CVE-2025-59513: Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to discl Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to disclose information locally.
nvd
CVE-2011-1263P4MEDIUMCVSS 4.3vr22011-08-10
CVE-2011-1263 [MEDIUM] CWE-79 CVE-2011-1263: Cross-site scripting (XSS) vulnerability in the logon page in Remote Desktop Web Access (RD Web Acce Cross-site scripting (XSS) vulnerability in the logon page in Remote Desktop Web Access (RD Web Access) in Microsoft Windows Server 2008 R2 and R2 SP1 allows remote attackers to inject arbitrary web script or HTML via the URI, aka "Remote Desktop Web Access Vulnerability."
nvd
CVE-2020-0607P4MEDIUMCVSS 5.5vr22020-01-14
CVE-2020-0607 [MEDIUM] CVE-2020-0607: An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Information Disclosure Vulnerability'.
nvd
CVE-2014-0323P4MEDIUMCVSS 6.6vr22014-03-12
CVE-2014-0323 [MEDIUM] CWE-200 CVE-2014-0323: win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to obtain sensitive information from kernel memory or cause a denial of service
nvd
CVE-2017-0042P4LOWCVSS 3.1vr22017-03-17
CVE-2017-0042 [LOW] CWE-200 CVE-2017-0042: Windows Media Player in Microsoft Windows 8.1; Windows Server 2012 R2; Windows RT 8.1; Windows 7 SP1 Windows Media Player in Microsoft Windows 8.1; Windows Server 2012 R2; Windows RT 8.1; Windows 7 SP1; Windows 2008 SP2 and R2 SP1, Windows Server 2016; Windows Vista SP2; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information via a crafted web site, aka "Windows Media Player Information Disclosure Vulnerability."
nvd
CVE-2015-1758P4MEDIUMCVSS 6.9vr22015-06-10
CVE-2015-1758 [MEDIUM] CVE-2015-1758: Untrusted search path vulnerability in the LoadLibrary function in the kernel in Microsoft Windows V Untrusted search path vulnerability in the LoadLibrary function in the kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a Trojan horse DLL in an unspecified directory, aka "Windows LoadLibrary EoP Vulnerability."
nvd
CVE-2015-1702P4MEDIUMCVSS 6.9vr22015-05-13
CVE-2015-1702 [MEDIUM] CWE-264 CVE-2015-1702: The Service Control Manager (SCM) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows S The Service Control Manager (SCM) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "
nvd
CVE-2019-1096P4MEDIUMCVSS 5.5vr22019-07-15
CVE-2019-1096 [MEDIUM] CWE-200 CVE-2019-1096: An information disclosure vulnerability exists when the win32k component improperly provides kernel An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.
nvd
CVE-2023-35377P4MEDIUMCVSS 6.5vr22023-08-08
CVE-2023-35377 [MEDIUM] CWE-20 CVE-2023-35377: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2023-35376P4MEDIUMCVSS 6.5vr22023-08-08
CVE-2023-35376 [MEDIUM] CWE-20 CVE-2023-35376: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2023-28266P4MEDIUMCVSS 5.5vr22023-04-11
CVE-2023-28266 [MEDIUM] CWE-126 CVE-2023-28266: Windows Common Log File System Driver Information Disclosure Vulnerability Windows Common Log File System Driver Information Disclosure Vulnerability
nvd
CVE-2023-36909P4MEDIUMCVSS 6.5vr22023-08-08
CVE-2023-36909 [MEDIUM] CWE-191 CVE-2023-36909: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
Microsoft Windows Server 2008 vulnerabilities | cvebase