cbcvebase.

Microsoft Windows Server 2008 vulnerabilities

3,037 known vulnerabilities affecting microsoft/windows_server_2008.

Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39

Vulnerabilities

Page 99 of 152
CVE-2014-0256P4MEDIUMCVSS 5.0vr22014-05-14
CVE-2014-0256 [MEDIUM] CWE-20 CVE-2014-0256: Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold allow remote attackers to cause a Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold allow remote attackers to cause a denial of service (iSCSI service outage) by sending many crafted packets, aka "iSCSI Target Remote Denial of Service Vulnerability."
nvd
CVE-2025-50166P3MEDIUMCVSS 6.5vr22025-08-12
CVE-2025-50166 [MEDIUM] CWE-190 CVE-2025-50166: Integer overflow or wraparound in Windows Distributed Transaction Coordinator allows an authorized a Integer overflow or wraparound in Windows Distributed Transaction Coordinator allows an authorized attacker to disclose information over a network.
nvd
CVE-2015-0087P3MEDIUMCVSS 5.0vr22015-03-11
CVE-2015-0087 [MEDIUM] CWE-200 CVE-2015-0087: Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to obtain sensitive information from kernel memory, and possibly bypass the KASLR protection mechanism, via a crafted
nvd
CVE-2020-1287P3HIGHCVSS 7.8vr22020-06-09
CVE-2020-1287 [HIGH] CVE-2020-1287: An elevation of privilege vulnerability exists in the way that the Windows WalletService handles obj An elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory, aka 'Windows WalletService Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1294.
nvd
CVE-2020-1291P3HIGHCVSS 7.8vr22020-06-09
CVE-2020-1291 [HIGH] CVE-2020-1291: An elevation of privilege vulnerability exists in the way that the Windows Network Connections Servi An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'.
nvd
CVE-2025-21181P3HIGHCVSS 7.5vr22025-02-11
CVE-2025-21181 [HIGH] CWE-400 CVE-2025-21181: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2017-0271P3MEDIUMCVSS 5.9vr22017-05-12
CVE-2017-0271 [MEDIUM] CVE-2017-0271: Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vul
nvd
CVE-2015-0089P3MEDIUMCVSS 5.0vr22015-03-11
CVE-2015-0089 [MEDIUM] CVE-2015-0089: Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to obtain sensitive information from kernel memory, and possibly bypass the KASLR protection mechanism, via a crafted font, ak
nvd
CVE-2017-11816P3MEDIUMCVSS 5.5vr22017-10-13
CVE-2017-11816 [MEDIUM] CWE-200 CVE-2017-11816: The Microsoft Windows Graphics Device Interface (GDI) on Microsoft Windows Server 2008 SP2 and R2 SP The Microsoft Windows Graphics Device Interface (GDI) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability in the way it handles objects in memory, aka "Windows GDI Inf
nvd
CVE-2019-0838P3HIGHCVSS 7.8vr22019-04-09
CVE-2019-0838 [HIGH] CVE-2019-0838: An information disclosure vulnerability exists when Windows Task Scheduler improperly discloses cred An information disclosure vulnerability exists when Windows Task Scheduler improperly discloses credentials to Windows Credential Manager, aka 'Windows Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0839.
nvd
CVE-2017-0267P3MEDIUMCVSS 5.9vr22017-05-12
CVE-2017-0267 [MEDIUM] CWE-200 CVE-2017-0267: Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclo
nvd
CVE-2015-1716P3MEDIUMCVSS 5.0vr22015-05-13
CVE-2015-1716 [MEDIUM] CWE-200 CVE-2015-1716: Schannel in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1 Schannel in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly restrict Diffie-Hellman Ephemeral (DHE) key lengths, which makes it easier for remote attackers to defeat cryptographic protection me
nvd
CVE-2024-26215P3HIGHCVSS 7.5vr22024-04-09
CVE-2024-26215 [HIGH] CWE-400 CVE-2024-26215: DHCP Server Service Denial of Service Vulnerability DHCP Server Service Denial of Service Vulnerability
nvd
CVE-2020-0637P3MEDIUMCVSS 6.5vr22020-01-14
CVE-2020-0637 [MEDIUM] CVE-2020-0637: An information disclosure vulnerability exists when Remote Desktop Web Access improperly handles cre An information disclosure vulnerability exists when Remote Desktop Web Access improperly handles credential information, aka 'Remote Desktop Web Access Information Disclosure Vulnerability'.
nvd
CVE-2025-21300P3HIGHCVSS 7.5vr22025-01-14
CVE-2025-21300 [HIGH] CWE-400 CVE-2025-21300: Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability
nvd
CVE-2024-38236P3HIGHCVSS 7.5vr22024-09-10
CVE-2024-38236 [HIGH] CWE-400 CVE-2024-38236: DHCP Server Service Denial of Service Vulnerability DHCP Server Service Denial of Service Vulnerability
nvd
CVE-2020-0754P3HIGHCVSS 7.8vr22020-02-11
CVE-2020-0754 [HIGH] CVE-2020-0754: An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0753.
nvd
CVE-2017-0050P3HIGHCVSS 7.8vr22017-03-17
CVE-2017-0050 [HIGH] CVE-2017-0050: The kernel API in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7; Window The kernel API in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7; Windows 8; Windows 10 Gold, 1511, and 1607; Windows RT 8.1; Windows Server 2012 Gold and R2; and Windows Server 2016 does not properly enforce permissions, which allows local users to spoof processes, spoof inter-process communication, or cause a denial of service via
nvd
CVE-2018-8562P3HIGHCVSS 7.8vr2-sp1v32-bit Systems Service Pack 2+4 more2018-11-14
CVE-2018-8562 [HIGH] CWE-404 CVE-2018-8562: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server
nvd
CVE-2019-1393P3HIGHCVSS 7.8vr22019-11-12
CVE-2019-1393 [HIGH] CWE-787 CVE-2019-1393: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1394, CVE-2019-1395, CVE-2019-1396, CVE-2019-1408, CVE-2019-1434.
nvd
Microsoft Windows Server 2008 vulnerabilities | cvebase