Windows Server 2019
by Microsoft
CVEs (4,947)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-0794 | Hig | 0.58 | 8.8 | 0.15 | Apr 9, 2019 | A remote code execution vulnerability exists when OLE automation improperly handles objects in memory, aka 'OLE Automation Remote Code Execution Vulnerability'. | ||
| CVE-2019-0790 | Hig | 0.58 | 8.8 | 0.16 | Apr 9, 2019 | A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0791, CVE-2019-0792, CVE-2019-0793, CVE-2019-0795. | ||
| CVE-2019-0772 | Hig | 0.58 | 8.8 | 0.13 | Apr 9, 2019 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0665, CVE-2019-0666, CVE-2019-0667. | ||
| CVE-2019-0765 | Hig | 0.58 | 8.8 | 0.14 | Apr 9, 2019 | A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory, aka 'Comctl32 Remote Code Execution Vulnerability'. | ||
| CVE-2019-0756 | Hig | 0.58 | 8.8 | 0.13 | Apr 9, 2019 | A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. | ||
| CVE-2019-0662 | Hig | 0.58 | 8.8 | 0.15 | Mar 5, 2019 | A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0618. | ||
| CVE-2019-0633 | Hig | 0.58 | 8.8 | 0.13 | Mar 5, 2019 | A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server handles certain requests, aka 'Windows SMB Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0630. | ||
| CVE-2018-8634 | Hig | 0.58 | 8.8 | 0.15 | Dec 12, 2018 | A remote code execution vulnerability exists in Windows where Microsoft text-to-speech fails to properly handle objects in the memory, aka "Microsoft Text-To-Speech Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows… | ||
| CVE-2026-62823 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network. | ||
| CVE-2026-62822 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-62818 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network. | ||
| CVE-2026-62817 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network. | ||
| CVE-2026-62816 | Hig | 0.57 | 8.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network. | ||
| CVE-2026-62800 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. | ||
| CVE-2026-62795 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-62790 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. | ||
| CVE-2026-62785 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-62784 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network. | ||
| CVE-2026-49179 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-47653 | Hig | 0.57 | 8.8 | 0.01 | Jun 9, 2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
- risk 0.58cvss 8.8epss 0.15
A remote code execution vulnerability exists when OLE automation improperly handles objects in memory, aka 'OLE Automation Remote Code Execution Vulnerability'.
- risk 0.58cvss 8.8epss 0.16
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0791, CVE-2019-0792, CVE-2019-0793, CVE-2019-0795.
- risk 0.58cvss 8.8epss 0.13
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0665, CVE-2019-0666, CVE-2019-0667.
- risk 0.58cvss 8.8epss 0.14
A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory, aka 'Comctl32 Remote Code Execution Vulnerability'.
- risk 0.58cvss 8.8epss 0.13
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'.
- risk 0.58cvss 8.8epss 0.15
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0618.
- risk 0.58cvss 8.8epss 0.13
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server handles certain requests, aka 'Windows SMB Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0630.
- risk 0.58cvss 8.8epss 0.15
A remote code execution vulnerability exists in Windows where Microsoft text-to-speech fails to properly handle objects in the memory, aka "Microsoft Text-To-Speech Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows…
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.
- risk 0.57cvss 8.8epss 0.01
Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.
- risk 0.57cvss 8.8epss 0.00
Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Page 19 of 248