cbcvebase.

Microsoft Windows Server 2008 vulnerabilities

3,037 known vulnerabilities affecting microsoft/windows_server_2008.

Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39

Vulnerabilities

Page 138 of 152
CVE-2023-28251P4MEDIUMCVSS 5.5vr22023-05-09
CVE-2023-28251 [MEDIUM] CVE-2023-28251: Windows Driver Revocation List Security Feature Bypass Vulnerability Windows Driver Revocation List Security Feature Bypass Vulnerability
nvd
CVE-2025-21189P4MEDIUMCVSS 4.3vr22025-01-14
CVE-2025-21189 [MEDIUM] CWE-41 CVE-2025-21189: MapUrlToZone Security Feature Bypass Vulnerability MapUrlToZone Security Feature Bypass Vulnerability
nvd
CVE-2010-1886P4MEDIUMCVSS 6.8vr22010-08-16
CVE-2010-1886 [MEDIUM] CWE-264 CVE-2010-1886: Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2, and Windows 7 allow local users to gain privileges by leveraging access to a process with NetworkService credentials, as demonstrated by TAPI Server, SQL Server, and IIS processes, and related to the Windows Service Isolation feature.
nvd
CVE-2022-34728P4MEDIUMCVSS 5.5vr22022-09-13
CVE-2022-34728 [MEDIUM] CVE-2022-34728: Windows Graphics Component Information Disclosure Vulnerability Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2022-26935P4MEDIUMCVSS 6.5vr2vsp22022-05-10
CVE-2022-26935 [MEDIUM] CVE-2022-26935: Windows WLAN AutoConfig Service Information Disclosure Vulnerability Windows WLAN AutoConfig Service Information Disclosure Vulnerability
nvd
CVE-2023-36908P4MEDIUMCVSS 6.5vr22023-08-08
CVE-2023-36908 [MEDIUM] CWE-200 CVE-2023-36908: Windows Hyper-V Information Disclosure Vulnerability Windows Hyper-V Information Disclosure Vulnerability
nvd
CVE-2020-1267P4MEDIUMCVSS 4.9vr22020-07-14
CVE-2020-1267 [MEDIUM] CVE-2020-1267: This security update corrects a denial of service in the Local Security Authority Subsystem Service This security update corrects a denial of service in the Local Security Authority Subsystem Service (LSASS) caused when an authenticated attacker sends a specially crafted authentication request, aka 'Local Security Authority Subsystem Service Denial of Service Vulnerability'.
nvd
CVE-2021-1656P4MEDIUMCVSS 5.5vr22021-01-12
CVE-2021-1656 [MEDIUM] CVE-2021-1656: TPM Device Driver Information Disclosure Vulnerability TPM Device Driver Information Disclosure Vulnerability
nvd
CVE-2015-0095P4MEDIUMCVSS 5.6vr22015-03-11
CVE-2015-0095 [MEDIUM] CWE-476 CVE-2015-0095: The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to cause a denial of service (NULL pointer dereference and blue screen), or obtain sensitive information from kernel m
nvd
CVE-2017-8474P4MEDIUMCVSS 5.0vr22017-06-15
CVE-2017-8474 [MEDIUM] CVE-2017-8474: The kernel in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 The kernel in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application. aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerabili
nvd
CVE-2018-8336P4MEDIUMCVSS 5.5vr2-sp1v32-bit Systems Service Pack 2+4 more2018-09-13
CVE-2018-8336 [MEDIUM] CWE-200 CVE-2018-8336: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8419, CVE-2018-8442, CVE-2018-8443, CVE-2018-8445, CVE-2018-8446.
nvd
CVE-2018-8330P4MEDIUMCVSS 5.5vr2-sp1v32-bit Systems Service Pack 2+4 more2018-10-10
CVE-2018-8330 [MEDIUM] CWE-200 CVE-2018-8330: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2,
nvd
CVE-2017-0297P4MEDIUMCVSS 5.0vr22017-06-15
CVE-2017-0297 [MEDIUM] CWE-200 CVE-2017-0297: The kernel in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 The kernel in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application. aka "Windows Kernel Information Disclosure Vulnerability," a different vul
nvd
CVE-2017-8475P4MEDIUMCVSS 5.0vr22017-06-15
CVE-2017-8475 [MEDIUM] CVE-2017-8475: Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an authenticated attacker to run a specially crafted application when the Windows kernel improperly initializes objects in memory, aka "Win32k Information Disclosure Vulnerability". This CVE ID is unique
nvd
CVE-2011-1894P4MEDIUMCVSS 4.3vr22011-06-16
CVE-2011-1894 [MEDIUM] CWE-79 CVE-2011-1894: The MHTML protocol handler in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vis The MHTML protocol handler in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle a MIME format in a request for embedded content in an HTML document, which allows remote attackers to conduct cross-site scripting (XSS) at
nvd
CVE-2017-11835P4MEDIUMCVSS 5.5vr22017-11-15
CVE-2017-11835 [MEDIUM] CVE-2017-11835: Microsoft graphics in Windows 7 SP1 and Windows Server 2008 SP2 and R2 SP1 allows an attacker to pot Microsoft graphics in Windows 7 SP1 and Windows Server 2008 SP2 and R2 SP1 allows an attacker to potentially read data that was not intended to be disclosed due to the way that the Microsoft Windows Embedded OpenType (EOT) font engine parses specially crafted embedded fonts, aka "Windows EOT Font Engine Information Disclosure Vulnerability". This CVE ID is
nvd
CVE-2019-0755P4MEDIUMCVSS 5.5vr22019-04-09
CVE-2019-0755 [MEDIUM] CVE-2019-0755: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0702, CVE-2019-0767, CVE-2019-0775, CVE-2019-0782.
nvd
CVE-2019-0663P4MEDIUMCVSS 5.5vr22019-03-05
CVE-2019-0663 [MEDIUM] CVE-2019-0663: An information disclosure vulnerability exists when the Windows kernel improperly initializes object An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.To exploit this vulnerability, an authenticated attacker could run a specially crafted application, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0621, CVE-2019-0661.
nvd
CVE-2018-0760P4MEDIUMCVSS 5.5vr22018-02-15
CVE-2018-0760 [MEDIUM] CVE-2018-0760: The Microsoft Windows Embedded OpenType (EOT) font engine in Microsoft Windows 7 SP1, Windows Server The Microsoft Windows Embedded OpenType (EOT) font engine in Microsoft Windows 7 SP1, Windows Server 2008 R2, and Windows Server 2012 allows information disclosure, due to how the Windows EOT font engine handles embedded fonts, aka "Windows EOT Font Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0755, CVE-2018-0761, and CVE-
nvd
CVE-2018-8427P4MEDIUMCVSS 5.5v32-bit Systems Service Pack 2v32-bit Systems Service Pack 2 (Server Core installation)+3 more2018-10-10
CVE-2018-8427 [MEDIUM] CWE-200 CVE-2018-8427: An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka "Microsoft Graphics Components Information Disclosure Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Office 365 ProPlus, Windows Server 2008, Microsoft PowerPoint Viewer, Microsoft Excel Viewer.
nvd
Microsoft Windows Server 2008 vulnerabilities | cvebase