cbcvebase.

Microsoft Windows Server 2008 vulnerabilities

3,037 known vulnerabilities affecting microsoft/windows_server_2008.

Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39

Vulnerabilities

Page 22 of 152
CVE-2012-0173P2CRITICALCVSS 9.3vr22012-06-12
CVE-2012-0173 [CRITICAL] CVE-2012-0173: The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process packets in memory, which allows remote attackers to execute arbitrary code by sending crafted RDP packets triggering access to an objec
nvd
CVE-2019-0853P2HIGHCVSS 8.8vr22019-04-09
CVE-2019-0853 [HIGH] CWE-824 CVE-2019-0853: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface ( A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
nvd
CVE-2014-1818P2CRITICALCVSS 9.3vr22014-06-11
CVE-2014-1818 [CRITICAL] CWE-20 CVE-2014-1818: GDI+ in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Wi GDI+ in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Office 2007 SP3 and 2010 SP1 and SP2, Live Meeting 2007 Console, Lync 2010 and 2013, Lync 2010 Attendee, and Lync Basic 2013 allows remote attackers to execu
nvd
CVE-2011-1873P2CRITICALCVSS 9.3vr22011-06-16
CVE-2011-1873 [CRITICAL] CWE-20 CVE-2011-1873: win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 on 64-bit platforms does not properly validate pointers during the parsing of OpenType (aka OTF) fonts, which allows remote attackers to execute arbitrary code
nvd
CVE-2011-3417P2CRITICALCVSS 9.3vr22011-12-30
CVE-2011-3417 [CRITICAL] CWE-264 CVE-2011-3417: The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 S The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0, when sliding expiry is enabled, does not properly handle cached content, which allows remote attackers to obtain access to arbitrary user accounts via a crafted URL, aka "ASP.NET Forms Authentication Ticket Caching Vulnera
nvd
CVE-2019-0603P3HIGHCVSS 7.5vr22019-04-08
CVE-2019-0603 [HIGH] CVE-2019-0603: A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with elevated permissions on a target system. To exploit the vulnerability, an attacker could create a specially crafted request, causing Windows to
nvd
CVE-2015-0092P2CRITICALCVSS 9.3vr22015-03-11
CVE-2015-0092 [CRITICAL] CVE-2015-0092: Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font Driver Remote Code Execution Vulnerability
nvd
CVE-2022-22012P2CRITICALCVSS 9.8vr2vsp22022-05-10
CVE-2022-22012 [CRITICAL] CVE-2022-22012: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-29130P2CRITICALCVSS 9.8vr22022-05-10
CVE-2022-29130 [CRITICAL] CVE-2022-29130: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2015-2515P3CRITICALCVSS 9.3vr22015-10-14
CVE-2015-2515 [CRITICAL] CWE-416 CVE-2015-2515: Use-after-free vulnerability in Windows Shell in Microsoft Windows Vista SP2, Windows Server 2008 SP Use-after-free vulnerability in Windows Shell in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows remote attackers to execute arbitrary code via a crafted toolbar object, aka "Toolbar Use After Free Vulnerability."
nvd
CVE-2012-0004P2CRITICALCVSS 9.3vr22012-01-10
CVE-2012-0004 [CRITICAL] CVE-2012-0004: Unspecified vulnerability in DirectShow in DirectX in Microsoft Windows XP SP2 and SP3, Windows Serv Unspecified vulnerability in DirectShow in DirectX in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted media file, related to Quartz.dll, Qdvd.dll, closed captioning, and the Line21 DirectShow filte
nvd
CVE-2015-2530P2CRITICALCVSS 9.3vr22015-09-09
CVE-2015-2530 [CRITICAL] CVE-2015-2530: Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, W Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows remote attackers to execute arbitrary code via a crafted .jnt file, aka "Windows Journal RCE Vulnerability," a different vulnerability than CVE-2015-2513 an
nvd
CVE-2023-35349P2CRITICALCVSS 9.8vr22023-10-10
CVE-2023-35349 [CRITICAL] CWE-20 CVE-2023-35349: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2015-2435P2CRITICALCVSS 9.3vr22015-08-15
CVE-2015-2435 [CRITICAL] CWE-20 CVE-2015-2435: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10, Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, Lync Basic 2013 SP1, and Silverlight before 5.1.40728 allow remote attacker
nvd
CVE-2017-0118P3MEDIUMCVSS 4.3PoCvr22017-03-17
CVE-2017-0118 [MEDIUM] CVE-2017-0118: Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerabili
nvd
CVE-2024-38074P2CRITICALCVSS 9.8vr22024-07-09
CVE-2024-38074 [CRITICAL] CWE-191 CVE-2024-38074: Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
nvd
CVE-2011-0658P2CRITICALCVSS 9.3vr22011-06-16
CVE-2011-0658 [CRITICAL] CWE-189 CVE-2011-0658: Integer underflow in the OLE Automation protocol implementation in VBScript.dll in Microsoft Windows Integer underflow in the OLE Automation protocol implementation in VBScript.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted WMF file, aka "OLE Automation Underflow Vuln
nvd
CVE-2012-2556P2CRITICALCVSS 9.3vr22012-12-12
CVE-2012-2556 [CRITICAL] CWE-94 CVE-2012-2556: The OpenType Font (OTF) driver in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windo The OpenType Font (OTF) driver in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to execute arbitrary code via a crafted OpenType font file, aka "OpenType Fon
nvd
CVE-2015-6097P2CRITICALCVSS 9.3vr22015-11-11
CVE-2015-6097 [CRITICAL] CWE-119 CVE-2015-6097: Heap-based buffer overflow in Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP Heap-based buffer overflow in Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted Journal (.jnt) file, aka "Windows Journal Heap Overflow Vulnerability."
nvd
CVE-2025-29962P2HIGHCVSS 8.8vr22025-05-13
CVE-2025-29962 [HIGH] CWE-122 CVE-2025-29962: Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a n Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
nvd
Microsoft Windows Server 2008 vulnerabilities | cvebase