VendorsMicrosoftwindows_server_2008any version
Vulnerabilities

Microsoft Windows Server 2008 for 32-bit Systems any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3613CVEs
CVE-2011-1871
Tcpip.sys in the TCP/IP stack in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (reboot) via a series of crafted ICMP messages, aka "ICMP Denial of Service Vulnerability."
Published 2011-08-10 · Modified
7.8EPSS 0.385
CVE-2016-0099
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 does not properly process request handles, which allows local users to gain privileges via a crafted application, aka "Secondary Logon Elevation of Privilege Vulnerability."
Published 2016-03-09 · Analyzed
7.8KEV4 PoCEPSS 0.368
CVE-2009-1926
Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to cause a denial of service (TCP outage) via a series of TCP sessions that have pending data and a (1) small or (2) zero receive window size, and remain in the FIN-WAIT-1 or FIN-WAIT-2 state indefinitely, aka "TCP/IP Orphaned Connections Vulnerability."
Published 2009-09-08 · Modified
7.8EPSS 0.350
CVE-2015-2387
ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "ATMFD.DLL Memory Corruption Vulnerability."
Published 2015-07-14 · Analyzed
7.8KEVEPSS 0.349
CVE-2010-2552
Stack consumption vulnerability in the SMB Server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to cause a denial of service (system hang) via a malformed SMBv2 compounded request, aka "SMB Stack Exhaustion Vulnerability."
Published 2010-08-11 · Modified
7.8EPSS 0.326
CVE-2018-5391
The Linux kernel, versions 3.9+, IP implementation is vulnerable to denial of service conditions with low rates of specially modified packets
Published 2018-09-06 · Modified
7.8EPSS 0.324
CVE-2013-0005
The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Framework 3.5, 3.5 SP1, 3.5.1, and 4, and the Management OData IIS Extension on Windows Server 2012, allows remote attackers to cause a denial of service (resource consumption and daemon restart) via crafted values in HTTP requests, aka "Replace Denial of Service Vulnerability."
Published 2013-01-09 · Modified
7.8EPSS 0.321
CVE-2009-1928
Stack consumption vulnerability in the LDAP service in Active Directory on Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2; Active Directory Application Mode (ADAM) on Windows XP SP2 and SP3 and Server 2003 SP2; and Active Directory Lightweight Directory Service (AD LDS) on Windows Server 2008 Gold and SP2 allows remote attackers to cause a denial of service (system hang) via a malformed (1) LDAP or (2) LDAPS request, aka "LSASS Recursive Stack Overflow Vulnerability."
Published 2009-11-11 · Modified
7.8EPSS 0.300
CVE-2019-1405
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'.
Published 2019-11-12 · Analyzed
7.8KEV2 PoCEPSS 0.300
CVE-2016-0016
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandle DLL loading, which allows local users to gain privileges via a crafted application, aka "DLL Loading Remote Code Execution Vulnerability."
Published 2016-01-13 · Modified
7.81 PoCEPSS 0.297
CVE-2010-4669
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Microsoft Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Windows 7 allows remote attackers to cause a denial of service (CPU consumption and system hang) by sending many Router Advertisement (RA) messages with different source addresses, as demonstrated by the flood_router6 program in the thc-ipv6 package.
Published 2011-01-07 · Modified
7.8EPSS 0.291
CVE-2024-38193
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Published 2024-08-13 · Analyzed
7.8KEV1 PoCEPSS 0.285
CVE-2009-2524
Integer underflow in the NTLM authentication feature in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to cause a denial of service (reboot) via a malformed packet, aka "Local Security Authority Subsystem Service Integer Overflow Vulnerability."
Published 2009-10-14 · Modified
7.8EPSS 0.285
CVE-2022-37969
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Published 2022-09-13 · Analyzed
7.8KEVEPSS 0.283
CVE-2024-49138
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Published 2024-12-10 · Analyzed
7.8KEV1 PoCEPSS 0.262
CVE-2020-0668
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0669, CVE-2020-0670, CVE-2020-0671, CVE-2020-0672.
Published 2020-02-11 · Modified
7.8EPSS 0.259
CVE-2024-35250
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
Published 2024-06-11 · Analyzed
7.8KEVEPSS 0.250
CVE-2016-0040
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows Elevation of Privilege Vulnerability."
Published 2016-02-10 · Analyzed
7.8KEV1 PoCEPSS 0.245
CVE-2011-1267
The SMB server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 request, aka "SMB Request Parsing Vulnerability."
Published 2011-06-16 · Modified
7.8EPSS 0.242
CVE-2024-26230
Windows Telephony Server Elevation of Privilege Vulnerability
Published 2024-04-09 · Analyzed
7.8EPSS 0.241
CVE-2022-35803
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Published 2022-09-13 · Modified
7.8EPSS 0.238
CVE-2016-0091
OLE in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted file, aka "Windows OLE Memory Remote Code Execution Vulnerability," a different vulnerability than CVE-2016-0092.
Published 2016-03-09 · Modified
7.8EPSS 0.231
CVE-2016-0051
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "WebDAV Elevation of Privilege Vulnerability."
Published 2016-02-10 · Modified
7.83 PoCEPSS 0.228
CVE-2021-34484
Windows User Profile Service Elevation of Privilege Vulnerability
Published 2021-08-12 · Analyzed
7.8KEVEPSS 0.218
CVE-2016-3309
The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3308, CVE-2016-3310, and CVE-2016-3311.
Published 2016-08-09 · Analyzed
7.8KEV1 PoCEPSS 0.205
CVE-2021-41379
Windows Installer Elevation of Privilege Vulnerability
Published 2021-11-10 · Analyzed
7.8KEVEPSS 0.195
CVE-2019-1215
An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1253, CVE-2019-1278, CVE-2019-1303.
Published 2019-09-11 · Analyzed
7.8KEV1 PoCEPSS 0.193
CVE-2022-22047
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
Published 2022-07-12 · Analyzed
7.8KEVEPSS 0.188
CVE-2022-22718
Windows Print Spooler Elevation of Privilege Vulnerability
Published 2022-02-09 · Analyzed
7.8KEVEPSS 0.185
CVE-2018-8440
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Published 2018-09-13 · Analyzed
7.8KEVEPSS 0.184
CVE-2023-36036
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Published 2023-11-14 · Analyzed
7.8KEVEPSS 0.167
CVE-2022-24481
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Published 2022-04-15 · Modified
7.8EPSS 0.166
CVE-2020-1048
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system, aka 'Windows Print Spooler Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1070.
Published 2020-05-21 · Modified
7.8EPSS 0.164
CVE-2017-11781
The Microsoft Server Block Message (SMB) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows a denial of service vulnerability when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability".
Published 2017-10-13 · Modified
7.8EPSS 0.144
CVE-2020-1337
Windows Print Spooler Elevation of Privilege Vulnerability
Published 2020-08-17 · Modified
7.8EPSS 0.141
CVE-2025-29824
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Published 2025-04-08 · Analyzed
7.8KEVEPSS 0.139
CVE-2016-0165
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0143 and CVE-2016-0167.
Published 2016-04-12 · Analyzed
7.8KEV1 PoCEPSS 0.137
CVE-2020-0708
A remote code execution vulnerability exists when the Windows Imaging Library improperly handles memory.To exploit this vulnerability, an attacker would first have to coerce a victim to open a specially crafted file.The security update addresses the vulnerability by correcting how the Windows Imaging Library handles memory., aka 'Windows Imaging Library Remote Code Execution Vulnerability'.
Published 2020-02-11 · Modified
7.8EPSS 0.135
CVE-2024-26158
Microsoft Install Service Elevation of Privilege Vulnerability
Published 2024-04-09 · Analyzed
7.8EPSS 0.123
CVE-2023-36424
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Published 2023-11-14 · Analyzed
7.8KEVEPSS 0.122
← Prev31 / 91Next →