cbcvebase.

Microsoft Windows Server 2008 vulnerabilities

3,037 known vulnerabilities affecting microsoft/windows_server_2008.

Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39

Vulnerabilities

Page 146 of 152
CVE-2021-38635P4MEDIUMCVSS 5.5vr22021-09-15
CVE-2021-38635 [MEDIUM] CVE-2021-38635: Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability
nvd
CVE-2021-36969P4MEDIUMCVSS 5.5vr22021-09-15
CVE-2021-36969 [MEDIUM] CVE-2021-36969: Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability
nvd
CVE-2023-36428P4MEDIUMCVSS 5.5vr22023-11-14
CVE-2023-36428 [MEDIUM] CWE-125 CVE-2023-36428: Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
nvd
CVE-2022-38043P4MEDIUMCVSS 5.5vr22022-10-11
CVE-2022-38043 [MEDIUM] CVE-2022-38043: Windows Security Support Provider Interface Information Disclosure Vulnerability Windows Security Support Provider Interface Information Disclosure Vulnerability
nvd
CVE-2017-8553P4MEDIUMCVSS 4.7vr22017-06-15
CVE-2017-8553 [MEDIUM] CWE-200 CVE-2017-8553: An information disclosure vulnerability exists in Microsoft Windows Server 2008 SP2 and R2 SP1, Wind An information disclosure vulnerability exists in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows Server 2016 when the Windows kernel improperly handles objects in memory, aka "GDI Information Disclosure Vulnerability".
nvd
CVE-2023-35341P4MEDIUMCVSS 5.5vr22023-07-11
CVE-2023-35341 [MEDIUM] CWE-190 CVE-2023-35341: Microsoft DirectMusic Information Disclosure Vulnerability Microsoft DirectMusic Information Disclosure Vulnerability
nvd
CVE-2022-35758P4MEDIUMCVSS 5.5vr22023-05-31
CVE-2022-35758 [MEDIUM] CVE-2022-35758: Windows Kernel Memory Information Disclosure Vulnerability Windows Kernel Memory Information Disclosure Vulnerability
nvd
CVE-2023-21697P4MEDIUMCVSS 5.5vr22023-02-14
CVE-2023-21697 [MEDIUM] CWE-126 CVE-2023-21697: Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability
nvd
CVE-2017-8486P4MEDIUMCVSS 4.7vr22017-07-11
CVE-2017-8486 [MEDIUM] CWE-200 CVE-2017-8486: Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an information disclosure due to the way it handles objects in memory, aka "Win32k Information Disclosure Vulnerability".
nvd
CVE-2017-11880P4MEDIUMCVSS 4.7vr22017-11-15
CVE-2017-11880 [MEDIUM] CVE-2017-11880: Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Windows Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to run a specially crafted application and obtain information to further compromise the user's system due to the Windows kernel improperly initializing obje
nvd
CVE-2017-11849P4MEDIUMCVSS 4.7vr22017-11-15
CVE-2017-11849 [MEDIUM] CVE-2017-11849: Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Server Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to log in and run a specially crafted application due to the Windows kernel improperly initializing a memory address, aka "Window
nvd
CVE-2017-11817P4MEDIUMCVSS 4.7vr22017-10-13
CVE-2017-11817 [MEDIUM] CWE-200 CVE-2017-11817: The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows an information disclosure vulnerability when it improperly validates objects in memory, aka "Windows Information Di
nvd
CVE-2024-38234P4MEDIUMCVSS 6.5vr22024-09-10
CVE-2024-38234 [MEDIUM] CWE-20 CVE-2024-38234: Windows Networking Denial of Service Vulnerability Windows Networking Denial of Service Vulnerability
nvd
CVE-2017-8676P4LOWCVSS 3.3vr22017-09-13
CVE-2017-8676 [LOW] CWE-200 CVE-2017-8676: The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, 1607, 1703, and Server 2016; Office 2007 SP3; Office 2010 SP2; Word Viewer; Office for Mac 2011 and 2016; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2
nvd
CVE-2018-8309P4MEDIUMCVSS 5.5vr2vr2-sp1+5 more2018-07-11
CVE-2018-8309 [MEDIUM] CVE-2018-8309: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka "Win A denial of service vulnerability exists when Windows improperly handles objects in memory, aka "Windows Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2018-8205P4MEDIUMCVSS 5.5vr2-sp12018-06-14
CVE-2018-8205 [MEDIUM] CVE-2018-8205: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka "Win A denial of service vulnerability exists when Windows improperly handles objects in memory, aka "Windows Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2019-1325P4MEDIUMCVSS 5.5vr22019-10-10
CVE-2019-1325 [MEDIUM] CVE-2019-1325: An elevation of privilege vulnerability exists in the Windows redirected drive buffering system (rdb An elevation of privilege vulnerability exists in the Windows redirected drive buffering system (rdbss.sys) when the operating system improperly handles specific local calls within Windows 7 for 32-bit systems, aka 'Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability'.
nvd
CVE-2022-34708P4MEDIUMCVSS 5.5vr22022-08-09
CVE-2022-34708 [MEDIUM] CWE-200 CVE-2022-34708: Windows Kernel Information Disclosure Vulnerability Windows Kernel Information Disclosure Vulnerability
nvd
CVE-2020-17036P4MEDIUMCVSS 5.5vr22020-11-11
CVE-2020-17036 [MEDIUM] CVE-2020-17036: Windows Function Discovery SSDP Provider Information Disclosure Vulnerability Windows Function Discovery SSDP Provider Information Disclosure Vulnerability
nvd
CVE-2017-0076P4MEDIUMCVSS 5.4vr22017-03-17
CVE-2017-0076 [MEDIUM] CVE-2017-0076: Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 and R2; Windows 10, 1511, and 1607; and Windows Server 2016 allows guest OS users, running as virtual machines, to cause a denial of service via a crafted application, aka "Hyper-V Denial of Service Vulnerability." This vulnerability is
nvd
Microsoft Windows Server 2008 vulnerabilities | cvebase