VYPR

Windows Server 2016

by Microsoft

CVEs (5,109)

  • CVE-2025-59198MedOct 14, 2025
    risk 0.33cvss 5.0epss 0.00

    Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally.

  • CVE-2024-43520MedOct 8, 2024
    risk 0.33cvss 5.0epss 0.01

    Windows Kernel Denial of Service Vulnerability

  • CVE-2024-26220MedApr 9, 2024
    risk 0.33cvss 5.0epss 0.01

    Windows Mobile Hotspot Information Disclosure Vulnerability

  • CVE-2021-1684MedJan 12, 2021
    risk 0.33cvss 5.0epss 0.02

    Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information regarding the vulnerability, please see this statement from the Bluetooth SIG. To address the vulnerability, Microsoft has released a software update that…

  • CVE-2021-1683MedJan 12, 2021
    risk 0.33cvss 5.0epss 0.02

    Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information regarding the vulnerability, please see this statement from the Bluetooth SIG. To address the vulnerability, Microsoft has released a software update that…

  • CVE-2021-1645MedJan 12, 2021
    risk 0.33cvss 5.0epss 0.07

    Windows Docker Information Disclosure Vulnerability

  • CVE-2020-16901MedOct 16, 2020
    risk 0.33cvss 5.0epss 0.01

    An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory. To exploit this vulnerability, an authenticated attacker could run a specially crafted application. An attacker who successfully exploited this…

  • CVE-2020-0837MedSep 11, 2020
    risk 0.33cvss 5.0epss 0.01

    An elevation of privilege vulnerability exists when Active Directory Federation Services (ADFS) improperly handles multi-factor authentication requests. An attacker who successfully exploited this vulnerability could bypass some, but not all, of the authentication…

  • CVE-2017-8475MedJun 15, 2017
    risk 0.33cvss 5.0epss 0.04

    Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an authenticated attacker to run a specially crafted application when the Windows kernel improperly initializes objects…

  • CVE-2017-8474MedJun 15, 2017
    risk 0.33cvss 5.0epss 0.04

    The kernel in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application.…

  • CVE-2017-0297MedJun 15, 2017
    risk 0.33cvss 5.0epss 0.04

    The kernel in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application.…

  • CVE-2017-0118MedMar 17, 2017
    risk 0.33cvss 4.3epss 0.23

    Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to obtain sensitive information from…

  • CVE-2024-20662MedJan 9, 2024
    risk 0.32cvss 4.9epss 0.02

    Windows Online Certificate Status Protocol (OCSP) Information Disclosure Vulnerability

  • CVE-2021-41337MedOct 13, 2021
    risk 0.32cvss 4.9epss 0.02

    Active Directory Security Feature Bypass Vulnerability

  • CVE-2020-1267MedJul 14, 2020
    risk 0.32cvss 4.9epss 0.05

    This security update corrects a denial of service in the Local Security Authority Subsystem Service (LSASS) caused when an authenticated attacker sends a specially crafted authentication request, aka 'Local Security Authority Subsystem Service Denial of Service Vulnerability'.

  • CVE-2019-1292MedSep 11, 2019
    risk 0.32cvss 4.9epss 0.05

    A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'.

  • CVE-2017-0190MedMay 12, 2017
    risk 0.32cvss 4.4epss 0.43

    The GDI component in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a…

  • CVE-2026-33829MedApr 14, 2026
    risk 0.31cvss 4.3epss 0.03

    Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2025-58719MedOct 14, 2025
    risk 0.31cvss 4.7epss 0.00

    Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54101MedSep 9, 2025
    risk 0.31cvss 4.8epss 0.03

    Use after free in Windows SMBv3 Client allows an authorized attacker to execute code over a network.

Page 236 of 256