VendorsMicrosoftwindows_server_2008any version
Vulnerabilities

Microsoft Windows Server 2008 for 32-bit Systems any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3613CVEs
CVE-2019-0974
Jet Database Engine Remote Code Execution Vulnerability
Published 2019-06-12 · Modified
9.3EPSS 0.041
CVE-2019-0905
Jet Database Engine Remote Code Execution Vulnerability
Published 2019-06-12 · Modified
9.3EPSS 0.041
CVE-2019-0904
Jet Database Engine Remote Code Execution Vulnerability
Published 2019-06-12 · Modified
9.3EPSS 0.041
CVE-2019-0907
Jet Database Engine Remote Code Execution Vulnerability
Published 2019-06-12 · Modified
9.3EPSS 0.041
CVE-2020-1564
Jet Database Engine Remote Code Execution Vulnerability
Published 2020-08-17 · Modified
9.3EPSS 0.040
CVE-2020-1562
Microsoft Graphics Components Remote Code Execution Vulnerability
Published 2020-08-17 · Modified
9.3EPSS 0.040
CVE-2010-1284
Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1286, CVE-2010-1287, CVE-2010-1289, CVE-2010-1290, and CVE-2010-1291.
Published 2010-05-13 · Modified
9.3EPSS 0.040
CVE-2010-1289
Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1284, CVE-2010-1286, CVE-2010-1287, CVE-2010-1290, and CVE-2010-1291.
Published 2010-05-13 · Modified
9.3EPSS 0.040
CVE-2020-1285
GDI+ Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
9.3EPSS 0.040
CVE-2020-1557
Jet Database Engine Remote Code Execution Vulnerability
Published 2020-08-17 · Modified
9.3EPSS 0.039
CVE-2020-1153
A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'.
Published 2020-05-21 · Modified
9.3EPSS 0.038
CVE-2020-1174
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1051, CVE-2020-1175, CVE-2020-1176.
Published 2020-05-21 · Modified
9.3EPSS 0.037
CVE-2020-1176
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1051, CVE-2020-1174, CVE-2020-1175.
Published 2020-05-21 · Modified
9.3EPSS 0.037
CVE-2020-1175
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1051, CVE-2020-1174, CVE-2020-1176.
Published 2020-05-21 · Modified
9.3EPSS 0.037
CVE-2020-1051
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1174, CVE-2020-1175, CVE-2020-1176.
Published 2020-05-21 · Modified
9.3EPSS 0.037
CVE-2019-0909
Jet Database Engine Remote Code Execution Vulnerability
Published 2019-06-12 · Modified
9.3EPSS 0.036
CVE-2010-1286
Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1284, CVE-2010-1287, CVE-2010-1289, CVE-2010-1290, and CVE-2010-1291.
Published 2010-05-13 · Modified
9.3EPSS 0.036
CVE-2010-1287
Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1284, CVE-2010-1286, CVE-2010-1289, CVE-2010-1290, and CVE-2010-1291.
Published 2010-05-13 · Modified
9.3EPSS 0.036
CVE-2010-1291
Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1284, CVE-2010-1286, CVE-2010-1287, CVE-2010-1289, and CVE-2010-1290.
Published 2010-05-13 · Modified
9.3EPSS 0.036
CVE-2020-1339
Windows Media Remote Code Execution Vulnerability
Published 2020-08-17 · Modified
9.3EPSS 0.034
CVE-2020-1061
A remote code execution vulnerability exists in the way that the Microsoft Script Runtime handles objects in memory, aka 'Microsoft Script Runtime Remote Code Execution Vulnerability'.
Published 2020-05-21 · Modified
9.3EPSS 0.033
CVE-2020-1508
Windows Media Audio Decoder Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
9.3EPSS 0.033
CVE-2022-24492
Remote Procedure Call Runtime Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
9.3EPSS 0.031
CVE-2019-1057
MS XML Remote Code Execution Vulnerability
Published 2019-08-14 · Modified
9.3EPSS 0.031
CVE-2022-24541
Windows Server Service Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
9.3EPSS 0.030
CVE-2022-26903
Windows Graphics Component Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
9.3EPSS 0.027
CVE-2022-30141
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Published 2022-06-15 · Modified
9.3EPSS 0.026
CVE-2022-26919
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
9.3EPSS 0.026
CVE-2011-4851
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation, as demonstrated by forms in server/google-tools/ and certain other files.
Published 2011-12-16 · Modified
9.3EPSS 0.019
CVE-2011-4854
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not ensure that Content-Type HTTP headers match the corresponding Content-Type data in HTML META elements, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving the get_enabled_product_icon program. NOTE: it is possible that only clients, not the Plesk product, could be affected by this issue.
Published 2011-12-16 · Modified
9.3EPSS 0.016
CVE-2011-4855
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 omits the Content-Type header's charset parameter for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving admin/customer-service-plan/list/reset-search/true/ and certain other files. NOTE: it is possible that only clients, not the Plesk product, could be affected by this issue.
Published 2011-12-16 · Modified
9.3EPSS 0.016
CVE-2011-4856
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving admin/health/parameters and certain other files. NOTE: it is possible that only clients, not the Plesk product, could be affected by this issue.
Published 2011-12-16 · Modified
9.3EPSS 0.016
CVE-2019-0719
A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0721.
Published 2019-11-12 · Modified
9.1EPSS 0.114
CVE-2023-21557
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
Published 2023-01-10 · Modified
9.1EPSS 0.020
CVE-2021-34527
Windows Print Spooler Remote Code Execution Vulnerability
Published 2021-07-02 · Analyzed
9.0KEVEPSS 0.998
CVE-2009-3023
Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authenticated users to execute arbitrary code via a crafted NLST (NAME LIST) command that uses wildcards, leading to memory corruption, aka "IIS FTP Service RCE and DoS Vulnerability."
Published 2009-08-31 · Modified
9.03 PoCEPSS 0.909
CVE-2014-6324
The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote authenticated domain users to obtain domain administrator privileges via a forged signature in a ticket, as exploited in the wild in November 2014, aka "Kerberos Checksum Vulnerability."
Published 2014-11-18 · Analyzed
9.0KEV1 PoCEPSS 0.873
CVE-2014-1812
The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not properly handle distribution of passwords, which allows remote authenticated users to obtain sensitive credential information and consequently gain privileges by leveraging access to the SYSVOL share, as exploited in the wild in May 2014, aka "Group Policy Preferences Password Elevation of Privilege Vulnerability."
Published 2014-05-14 · Analyzed
9.0KEVEPSS 0.649
CVE-2008-1436
Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 does not properly assign activities to the (1) NetworkService and (2) LocalService accounts, which might allow context-dependent attackers to gain privileges by using one service process to capture a resource from a second service process that has a LocalSystem privilege-escalation ability, related to improper management of the SeImpersonatePrivilege user right, as originally reported for Internet Information Services (IIS), aka Token Kidnapping.
Published 2008-04-21 · Modified
9.01 PoCEPSS 0.368
CVE-2009-0230
The Windows Print Spooler in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows remote authenticated users to gain privileges via a crafted RPC message that triggers loading of a DLL file from an arbitrary directory, aka "Print Spooler Load Library Vulnerability."
Published 2009-06-10 · Modified
9.0EPSS 0.349
← Prev17 / 91Next →