cbcvebase.

Microsoft Windows Server 2008 vulnerabilities

3,037 known vulnerabilities affecting microsoft/windows_server_2008.

Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39

Vulnerabilities

Page 90 of 152
CVE-2018-8424P3MEDIUMCVSS 6.5vr2-sp1vsp22018-09-13
CVE-2018-8424 [MEDIUM] CVE-2018-8424: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Wi
nvd
CVE-2020-1314P3HIGHCVSS 7.8vr22020-06-09
CVE-2020-1314 [HIGH] CVE-2020-1314: An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF server fails to properly handle messages sent from TSF clients, aka 'Windows Text Service Framework Elevation of Privilege Vulnerability'.
nvd
CVE-2021-1734P3HIGHCVSS 7.5vr22021-02-25
CVE-2021-1734 [HIGH] CVE-2021-1734: Windows Remote Procedure Call Information Disclosure Vulnerability Windows Remote Procedure Call Information Disclosure Vulnerability
nvd
CVE-2020-1478P3HIGHCVSS 7.8vr22020-08-17
CVE-2020-1478 [HIGH] CWE-787 CVE-2020-1478: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincin
nvd
CVE-2020-1015P3HIGHCVSS 7.8vr22020-04-15
CVE-2020-1015 [HIGH] CVE-2020-1015: An elevation of privilege vulnerability exists in the way that the User-Mode Power Service (UMPS) ha An elevation of privilege vulnerability exists in the way that the User-Mode Power Service (UMPS) handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0934, CVE-2020-0983, CVE-2020-1009, CVE-2020-1011.
nvd
CVE-2020-1477P3HIGHCVSS 7.8vr22020-08-17
CVE-2020-1477 [HIGH] CWE-787 CVE-2020-1477: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincin
nvd
CVE-2016-0050P3MEDIUMCVSS 5.3vr22016-02-10
CVE-2016-0050 [MEDIUM] CWE-20 CVE-2016-0050: Network Policy Server (NPS) in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and Network Policy Server (NPS) in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 misparses username queries, which allows remote attackers to cause a denial of service (RADIUS authentication outage) via crafted requests, aka "Network Policy Server RADIUS Implementation Denial of Service Vulnerability."
nvd
CVE-2021-43236P3HIGHCVSS 7.5vr22021-12-15
CVE-2021-43236 [HIGH] CVE-2021-43236: Microsoft Message Queuing Information Disclosure Vulnerability Microsoft Message Queuing Information Disclosure Vulnerability
nvd
CVE-2021-43222P3HIGHCVSS 7.5vr22021-12-15
CVE-2021-43222 [HIGH] CVE-2021-43222: Microsoft Message Queuing Information Disclosure Vulnerability Microsoft Message Queuing Information Disclosure Vulnerability
nvd
CVE-2024-21438P3HIGHCVSS 7.5vr22024-03-12
CVE-2024-21438 [HIGH] CWE-369 CVE-2024-21438: Microsoft AllJoyn API Denial of Service Vulnerability Microsoft AllJoyn API Denial of Service Vulnerability
nvd
CVE-2016-0020P3HIGHCVSS 7.8vr22016-01-13
CVE-2016-0020 [HIGH] CVE-2016-0020: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandle DLL loa Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandle DLL loading, which allows local users to gain privileges via a crafted application, aka "MAPI DLL Loading Elevation of Privilege Vulnerability."
nvd
CVE-2024-38031P3HIGHCVSS 7.5vr22024-07-09
CVE-2024-38031 [HIGH] CWE-400 CVE-2024-38031: Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
nvd
CVE-2024-38068P3HIGHCVSS 7.5vr22024-07-09
CVE-2024-38068 [HIGH] CWE-400 CVE-2024-38068: Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
nvd
CVE-2024-38067P3HIGHCVSS 7.5vr22024-07-09
CVE-2024-38067 [HIGH] CWE-400 CVE-2024-38067: Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
nvd
CVE-2016-7211P3HIGHCVSS 7.3vr22016-10-14
CVE-2016-7211 [HIGH] CVE-2016-7211: The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." a different vulnerability than CVE-2016-3266
nvd
CVE-2024-49121P3HIGHCVSS 7.5vr22024-12-12
CVE-2024-49121 [HIGH] CWE-476 CVE-2024-49121: Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
nvd
CVE-2016-0087P3HIGHCVSS 7.8vr22016-03-09
CVE-2016-0087 [HIGH] CWE-264 CVE-2016-0087: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 do not properly v Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 do not properly validate handles, which allows local users to gain privileges via a crafted application, aka "Windows Elevation of Privilege Vulnerability."
nvd
CVE-2024-43541P3HIGHCVSS 7.5vr22024-10-08
CVE-2024-43541 [HIGH] CWE-400 CVE-2024-43541: Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability
nvd
CVE-2017-0077P3HIGHCVSS 7.8vr22017-05-12
CVE-2017-0077 [HIGH] CVE-2017-0077: The kernel-mode drivers in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows S The kernel-mode drivers in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow a local authenticated attacker to execute a specially crafted application to obtain information, or in Windows 7 and later, cause denial of service, aka "Win3
nvd
CVE-2024-43515P3HIGHCVSS 7.5vr22024-10-08
CVE-2024-43515 [HIGH] CWE-400 CVE-2024-43515: Internet Small Computer Systems Interface (iSCSI) Denial of Service Vulnerability Internet Small Computer Systems Interface (iSCSI) Denial of Service Vulnerability
nvd
Microsoft Windows Server 2008 vulnerabilities | cvebase