Windows Server 2008
by Microsoft
CVEs (3,572)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2010-2554 | Hig | 0.54 | 7.8 | 0.02 | Aug 11, 2010 | The Tracing Feature for Services in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 has incorrect ACLs on its registry keys, which allows local users to gain privileges via vectors involving a named pipe and impersonation, aka "Tracing… | ||
| CVE-2010-1889 | Hig | 0.54 | 7.8 | 0.02 | Aug 11, 2010 | Double free vulnerability in the kernel in Microsoft Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2, allows local users to gain privileges via a crafted application, related to object initialization during error handling, aka "Windows Kernel Double Free… | ||
| CVE-2009-3671 | Hig | 0.54 | 8.1 | 0.21 | Dec 9, 2009 | Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption… | ||
| CVE-2009-2529 | Hig | 0.54 | 8.1 | 0.20 | Oct 14, 2009 | Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not properly handle argument validation for unspecified variables, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "HTML Component Handling Vulnerability." | ||
| CVE-2009-2502 | Hig | 0.54 | 8.1 | 0.22 | Oct 14, 2009 | Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003… | ||
| CVE-2025-50177 | Hig | 0.53 | 8.1 | 0.04 | Aug 12, 2025 | Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-33070 | Hig | 0.53 | 8.1 | 0.07 | Jun 10, 2025 | Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2025-32710 | Hig | 0.53 | 8.1 | 0.01 | Jun 10, 2025 | Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-26671 | Hig | 0.53 | 8.1 | 0.01 | Apr 8, 2025 | Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-26670 | Hig | 0.53 | 8.1 | 0.10 | Apr 8, 2025 | Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-26663 | Hig | 0.53 | 8.1 | 0.02 | Apr 8, 2025 | Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-24064 | Hig | 0.53 | 8.1 | 0.01 | Mar 11, 2025 | Use after free in DNS Server allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-24035 | Hig | 0.53 | 8.1 | 0.02 | Mar 11, 2025 | Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-21376 | Hig | 0.53 | 8.1 | 0.09 | Feb 11, 2025 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | ||
| CVE-2025-21297 | Hig | 0.53 | 8.1 | 0.01 | Jan 14, 2025 | Windows Remote Desktop Services Remote Code Execution Vulnerability | ||
| CVE-2025-21295 | Hig | 0.53 | 8.1 | 0.02 | Jan 14, 2025 | SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability | ||
| CVE-2025-21294 | Hig | 0.53 | 8.1 | 0.01 | Jan 14, 2025 | Microsoft Digest Authentication Remote Code Execution Vulnerability | ||
| CVE-2025-21285 | Hig | 0.53 | 7.5 | 0.56 | Jan 14, 2025 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | ||
| CVE-2024-49127 | Hig | 0.53 | 8.1 | 0.01 | Dec 12, 2024 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | ||
| CVE-2024-49126 | Hig | 0.53 | 8.1 | 0.01 | Dec 12, 2024 | Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability |
- risk 0.54cvss 7.8epss 0.02
The Tracing Feature for Services in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 has incorrect ACLs on its registry keys, which allows local users to gain privileges via vectors involving a named pipe and impersonation, aka "Tracing…
- risk 0.54cvss 7.8epss 0.02
Double free vulnerability in the kernel in Microsoft Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2, allows local users to gain privileges via a crafted application, related to object initialization during error handling, aka "Windows Kernel Double Free…
- risk 0.54cvss 8.1epss 0.21
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption…
- risk 0.54cvss 8.1epss 0.20
Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not properly handle argument validation for unspecified variables, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "HTML Component Handling Vulnerability."
- risk 0.54cvss 8.1epss 0.22
Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003…
- risk 0.53cvss 8.1epss 0.04
Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.07
Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network.
- risk 0.53cvss 8.1epss 0.01
Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.10
Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.02
Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Use after free in DNS Server allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.02
Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.09
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Remote Desktop Services Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.02
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Microsoft Digest Authentication Remote Code Execution Vulnerability
- risk 0.53cvss 7.5epss 0.56
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability
Page 38 of 179