cbcvebase.

Microsoft Windows Server 2016 vulnerabilities

4,536 known vulnerabilities affecting microsoft/windows_server_2016.

Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22

Vulnerabilities

Page 194 of 227
CVE-2018-8454P4MEDIUMCVSS 5.5v1709v18032018-11-14
CVE-2018-8454 [MEDIUM] CWE-200 CVE-2018-8454: An information disclosure vulnerability exists when Windows Audio Service fails to properly handle o An information disclosure vulnerability exists when Windows Audio Service fails to properly handle objects in memory, aka "Windows Audio Service Information Disclosure Vulnerability." This affects Windows 10 Servers, Windows 10, Windows Server 2019.
nvd
CVE-2018-0964P4MEDIUMCVSS 6.1v17092018-04-12
CVE-2018-0964 [MEDIUM] CVE-2018-0964: An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information Disclosure Vulnerability." This affects Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-0957.
nvd
CVE-2020-1267P4MEDIUMCVSS 4.9v1903v1909+1 more2020-07-14
CVE-2020-1267 [MEDIUM] CVE-2020-1267: This security update corrects a denial of service in the Local Security Authority Subsystem Service This security update corrects a denial of service in the Local Security Authority Subsystem Service (LSASS) caused when an authenticated attacker sends a specially crafted authentication request, aka 'Local Security Authority Subsystem Service Denial of Service Vulnerability'.
nvd
CVE-2021-1656P4MEDIUMCVSS 5.5v20h2v1909+2 more2021-01-12
CVE-2021-1656 [MEDIUM] CVE-2021-1656: TPM Device Driver Information Disclosure Vulnerability TPM Device Driver Information Disclosure Vulnerability
nvd
CVE-2018-8336P4MEDIUMCVSS 5.5v(Server Core installation)2018-09-13
CVE-2018-8336 [MEDIUM] CWE-200 CVE-2018-8336: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8419, CVE-2018-8442, CVE-2018-8443, CVE-2018-8445, CVE-2018-8446.
nvd
CVE-2021-24084P4MEDIUMCVSS 5.5v20h2v1909+1 more2021-02-25
CVE-2021-24084 [MEDIUM] CWE-59 CVE-2021-24084: Windows Mobile Device Management Information Disclosure Vulnerability Windows Mobile Device Management Information Disclosure Vulnerability
nvd
CVE-2018-8330P4MEDIUMCVSS 5.5v1709v1803+1 more2018-10-10
CVE-2018-8330 [MEDIUM] CWE-200 CVE-2018-8330: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2,
nvd
CVE-2019-0755P4MEDIUMCVSS 5.5v1709v18032019-04-09
CVE-2019-0755 [MEDIUM] CVE-2019-0755: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0702, CVE-2019-0767, CVE-2019-0775, CVE-2019-0782.
nvd
CVE-2019-0663P4MEDIUMCVSS 5.5v17092019-03-05
CVE-2019-0663 [MEDIUM] CVE-2019-0663: An information disclosure vulnerability exists when the Windows kernel improperly initializes object An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.To exploit this vulnerability, an authenticated attacker could run a specially crafted application, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0621, CVE-2019-0661.
nvd
CVE-2019-1293P4MEDIUMCVSS 5.5v1803v19032019-09-11
CVE-2019-1293 [MEDIUM] CWE-200 CVE-2019-1293: An information disclosure vulnerability exists in Windows when the Windows SMB Client kernel-mode dr An information disclosure vulnerability exists in Windows when the Windows SMB Client kernel-mode driver fails to properly handle objects in memory, aka 'Windows SMB Client Driver Information Disclosure Vulnerability'.
nvd
CVE-2019-0628P4MEDIUMCVSS 5.5v1709v18032019-03-05
CVE-2019-0628 [MEDIUM] CVE-2019-0628: An information disclosure vulnerability exists when the win32k component improperly provides kernel An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.
nvd
CVE-2019-0636P4MEDIUMCVSS 5.5v1709v18032019-03-05
CVE-2019-0636 [MEDIUM] CVE-2019-0636: An information vulnerability exists when Windows improperly discloses file information, aka 'Windows An information vulnerability exists when Windows improperly discloses file information, aka 'Windows Information Disclosure Vulnerability'.
nvd
CVE-2019-1440P4MEDIUMCVSS 5.5v1803v19032019-11-12
CVE-2019-1440 [MEDIUM] CVE-2019-1440: An information disclosure vulnerability exists when the win32k component improperly provides kernel An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1436.
nvd
CVE-2020-0744P4MEDIUMCVSS 5.5v1803v1903+1 more2020-02-11
CVE-2020-0744 [MEDIUM] CWE-125 CVE-2020-0744: An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka 'Windows GDI Information Disclosure Vulnerability'.
nvd
CVE-2019-0553P4MEDIUMCVSS 5.5v1709v18032019-01-08
CVE-2019-0553 [MEDIUM] CVE-2019-0553: An information disclosure vulnerability exists when Windows Subsystem for Linux improperly handles o An information disclosure vulnerability exists when Windows Subsystem for Linux improperly handles objects in memory, aka "Windows Subsystem for Linux Information Disclosure Vulnerability." This affects Windows 10 Servers, Windows 10, Windows Server 2019.
nvd
CVE-2019-0767P4MEDIUMCVSS 5.5v1709v18032019-04-09
CVE-2019-0767 [MEDIUM] CVE-2019-0767: An information disclosure vulnerability exists when the Windows kernel improperly initializes object An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.To exploit this vulnerability, an authenticated attacker could run a specially crafted application, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0702, CVE-2019-0755, CVE-2019-0775, CVE-2019-0782.
nvd
CVE-2019-1097P4MEDIUMCVSS 5.5v1803v19032019-07-15
CVE-2019-1097 [MEDIUM] CVE-2019-1097: An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1093.
nvd
CVE-2019-1093P4MEDIUMCVSS 5.5v1803v19032019-07-15
CVE-2019-1093 [MEDIUM] CWE-200 CVE-2019-1093: An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1097.
nvd
CVE-2019-1251P4MEDIUMCVSS 5.5v1803v19032019-09-11
CVE-2019-1251 [MEDIUM] CVE-2019-1251: An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1244, CVE-2019-1245.
nvd
CVE-2019-1219P4MEDIUMCVSS 5.5v1803v19032019-09-11
CVE-2019-1219 [MEDIUM] CWE-200 CVE-2019-1219: An information disclosure vulnerability exists when the Windows Transaction Manager improperly handl An information disclosure vulnerability exists when the Windows Transaction Manager improperly handles objects in memory, aka 'Windows Transaction Manager Information Disclosure Vulnerability'.
nvd
Microsoft Windows Server 2016 vulnerabilities | cvebase