Microsoft Windows Server 2008 vulnerabilities
3,037 known vulnerabilities affecting microsoft/windows_server_2008.
Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39
Vulnerabilities
Page 142 of 152
CVE-2019-1469P4MEDIUMCVSS 5.5vr22019-12-10
CVE-2019-1469 [MEDIUM] CWE-200 CVE-2019-1469: An information disclosure vulnerability exists when the win32k component improperly provides kernel
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.
nvd
CVE-2020-1141P4MEDIUMCVSS 5.5vr22020-05-21
CVE-2020-1141 [MEDIUM] CVE-2020-1141: An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface
An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0963, CVE-2020-1145, CVE-2020-1179.
nvd
CVE-2019-1283P4MEDIUMCVSS 5.5vr22019-09-11
CVE-2019-1283 [MEDIUM] CWE-200 CVE-2019-1283: An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle
An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Information Disclosure Vulnerability'.
nvd
CVE-2019-0782P4MEDIUMCVSS 5.5vr22019-04-09
CVE-2019-0782 [MEDIUM] CVE-2019-0782: An information disclosure vulnerability exists when the Windows kernel fails to properly initialize
An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0702, CVE-2019-0755, CVE-2019-0767, CVE-2019-0775.
nvd
CVE-2019-0702P4MEDIUMCVSS 5.5vr22019-04-09
CVE-2019-0702 [MEDIUM] CVE-2019-0702: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0755, CVE-2019-0767, CVE-2019-0775, CVE-2019-0782.
nvd
CVE-2020-0755P4MEDIUMCVSS 5.5vr22020-02-11
CVE-2020-0755 [MEDIUM] CVE-2020-0755: An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service whe
An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to properly handle objects in memory.To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.The security update addresses the vulnerability by correcting how the service handles o
nvd
CVE-2020-0748P4MEDIUMCVSS 5.5vr22020-02-11
CVE-2020-0748 [MEDIUM] CVE-2020-0748: An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service whe
An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to properly handle objects in memory.To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.The security update addresses the vulnerability by correcting how the service handles o
nvd
CVE-2020-0677P4MEDIUMCVSS 5.5vr22020-02-11
CVE-2020-0677 [MEDIUM] CVE-2020-0677: An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service whe
An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to properly handle objects in memory.To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.The security update addresses the vulnerability by correcting how the service handles o
nvd
CVE-2020-0675P4MEDIUMCVSS 5.5vr22020-02-11
CVE-2020-0675 [MEDIUM] CVE-2020-0675: An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service whe
An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to properly handle objects in memory.To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.The security update addresses the vulnerability by correcting how the service handles o
nvd
CVE-2020-0676P4MEDIUMCVSS 5.5vr22020-02-11
CVE-2020-0676 [MEDIUM] CVE-2020-0676: An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service whe
An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to properly handle objects in memory.To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.The security update addresses the vulnerability by correcting how the service handles o
nvd
CVE-2020-0756P4MEDIUMCVSS 5.5vr22020-02-11
CVE-2020-0756 [MEDIUM] CVE-2020-0756: An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service whe
An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to properly handle objects in memory.To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.The security update addresses the vulnerability by correcting how the service handles o
nvd
CVE-2020-1160P4MEDIUMCVSS 5.5vr22020-06-09
CVE-2020-1160 [MEDIUM] CVE-2020-1160: An information disclosure vulnerability exists when the Microsoft Windows Graphics Component imprope
An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'.
nvd
CVE-2020-16940P4MEDIUMCVSS 5.5vr22020-10-16
CVE-2020-16940 [MEDIUM] CWE-269 CVE-2020-16940: <p>An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) im
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles junction points. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then
nvd
CVE-2019-1474P4MEDIUMCVSS 5.5vr22019-12-10
CVE-2019-1474 [MEDIUM] CVE-2019-1474: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1472.
nvd
CVE-2017-8719P4MEDIUMCVSS 4.7vr22017-09-13
CVE-2017-8719 [MEDIUM] CVE-2017-8719: The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnera
nvd
CVE-2017-8709P4MEDIUMCVSS 4.7vr22017-09-13
CVE-2017-8709 [MEDIUM] CVE-2017-8709: The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnera
nvd
CVE-2016-7218P4MEDIUMCVSS 4.7vr22016-11-10
CVE-2016-7218 [MEDIUM] CWE-200 CVE-2016-7218: Bowser.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2
Bowser.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to obtain sensitive information via a crafted application, aka "Windows Bowser.sys Information
nvd
CVE-2020-0658P4MEDIUMCVSS 5.5vr22020-02-11
CVE-2020-0658 [MEDIUM] CVE-2020-0658: An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver w
An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle objects in memory, aka 'Windows Common Log File System Driver Information Disclosure Vulnerability'.
nvd
CVE-2020-0871P4MEDIUMCVSS 5.5vr22020-03-12
CVE-2020-0871 [MEDIUM] CVE-2020-0871: An information disclosure vulnerability exists when Windows Network Connections Service fails to pro
An information disclosure vulnerability exists when Windows Network Connections Service fails to properly handle objects in memory, aka 'Windows Network Connections Service Information Disclosure Vulnerability'.
nvd
CVE-2019-1274P4MEDIUMCVSS 5.5vr22019-09-11
CVE-2019-1274 [MEDIUM] CWE-665 CVE-2019-1274: An information disclosure vulnerability exists when the Windows kernel fails to properly initialize
An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka 'Windows Kernel Information Disclosure Vulnerability'.
nvd