VendorsMicrosoftwindows_server_2008r2
Vulnerabilities

Microsoft Windows Server 2008 for 32-bit Systems r2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3562CVEs
CVE-2025-21249
Windows Digital Media Elevation of Privilege Vulnerability
Published 2025-01-14 · Analyzed
6.6EPSS 0.008
CVE-2025-21227
Windows Digital Media Elevation of Privilege Vulnerability
Published 2025-01-14 · Analyzed
6.6EPSS 0.008
CVE-2025-21310
Windows Digital Media Elevation of Privilege Vulnerability
Published 2025-01-14 · Analyzed
6.6EPSS 0.008
CVE-2025-21324
Windows Digital Media Elevation of Privilege Vulnerability
Published 2025-01-14 · Analyzed
6.6EPSS 0.008
CVE-2025-21260
Windows Digital Media Elevation of Privilege Vulnerability
Published 2025-01-14 · Analyzed
6.6EPSS 0.008
CVE-2022-22048
BitLocker Security Feature Bypass Vulnerability
Published 2022-07-12 · Modified
6.6EPSS 0.008
CVE-2025-21265
Windows Digital Media Elevation of Privilege Vulnerability
Published 2025-01-14 · Analyzed
6.6EPSS 0.008
CVE-2025-21263
Windows Digital Media Elevation of Privilege Vulnerability
Published 2025-01-14 · Analyzed
6.6EPSS 0.008
CVE-2025-21261
Windows Digital Media Elevation of Privilege Vulnerability
Published 2025-01-14 · Analyzed
6.6EPSS 0.008
CVE-2025-21327
Windows Digital Media Elevation of Privilege Vulnerability
Published 2025-01-14 · Analyzed
6.6EPSS 0.008
CVE-2025-21341
Windows Digital Media Elevation of Privilege Vulnerability
Published 2025-01-14 · Analyzed
6.6EPSS 0.007
CVE-2023-35344
Windows DNS Server Remote Code Execution Vulnerability
Published 2023-07-11 · Modified
6.6EPSS 0.007
CVE-2023-35345
Windows DNS Server Remote Code Execution Vulnerability
Published 2023-07-11 · Modified
6.6EPSS 0.007
CVE-2023-35346
Windows DNS Server Remote Code Execution Vulnerability
Published 2023-07-11 · Modified
6.6EPSS 0.007
CVE-2023-35351
Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability
Published 2023-07-11 · Modified
6.6EPSS 0.007
CVE-2023-35310
Windows DNS Server Remote Code Execution Vulnerability
Published 2023-07-11 · Modified
6.6EPSS 0.007
CVE-2022-38032
Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability
Published 2022-10-11 · Modified
6.6EPSS 0.006
CVE-2024-43451
NTLM Hash Disclosure Spoofing Vulnerability
Published 2024-11-12 · Analyzed
6.5KEVEPSS 0.841
CVE-2019-1439
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
Published 2019-11-12 · Modified
6.5EPSS 0.754
CVE-2019-1252
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1286.
Published 2019-09-11 · Modified
6.5EPSS 0.604
CVE-2025-24054
NTLM Hash Disclosure Spoofing Vulnerability
Published 2025-03-11 · Analyzed
6.5KEV3 PoCEPSS 0.589
CVE-2022-23253
Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability
Published 2022-03-09 · Modified
6.5EPSS 0.564
CVE-2013-7331
The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC share pathnames, intranet hostnames, and intranet IP addresses by examining error codes, as demonstrated by a res:// URL, and exploited in the wild in February 2014.
Published 2014-02-26 · Analyzed
6.5KEVEPSS 0.502
CVE-2021-26414
Windows DCOM Server Security Feature Bypass
Published 2021-06-08 · Modified
6.5EPSS 0.498
CVE-2019-1009
Windows GDI Information Disclosure Vulnerability
Published 2019-06-12 · Modified
6.5EPSS 0.485
CVE-2016-0168
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to obtain sensitive information via a crafted document, aka "Windows Graphics Component Information Disclosure Vulnerability," a different vulnerability than CVE-2016-0169.
Published 2016-05-11 · Modified
6.51 PoCEPSS 0.432
CVE-2016-0169
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to obtain sensitive information via a crafted document, aka "Windows Graphics Component Information Disclosure Vulnerability," a different vulnerability than CVE-2016-0168.
Published 2016-05-11 · Modified
6.51 PoCEPSS 0.432
CVE-2025-21377
NTLM Hash Disclosure Spoofing Vulnerability
Published 2025-02-11 · Analyzed
6.5EPSS 0.399
CVE-2017-0063
The Color Management Module (ICM32.dll) memory handling functionality in Windows Vista SP2; Windows Server 2008 SP2 and R2; and Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to bypass ASLR and execute code in combination with another vulnerability through a crafted website, aka "Microsoft Color Management Information Disclosure Vulnerability." This vulnerability is different from that described in CVE-2017-0061.
Published 2017-03-17 · Modified
6.51 PoCEPSS 0.353
CVE-2015-0071
Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."
Published 2015-02-11 · Analyzed
6.5KEVEPSS 0.336
CVE-2016-3298
Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow remote attackers to determine the existence of arbitrary files via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."
Published 2016-10-14 · Analyzed
6.5KEVEPSS 0.333
CVE-2022-24502
Windows HTML Platforms Security Feature Bypass Vulnerability
Published 2022-03-09 · Modified
6.5EPSS 0.331
CVE-2025-50154
Microsoft Windows File Explorer Spoofing Vulnerability
Published 2025-08-12 · Modified
6.51 PoCEPSS 0.302
CVE-2016-3351
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
Published 2016-09-14 · Analyzed
6.5KEVEPSS 0.263
CVE-2016-7257
The GDI component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office for Mac 2011, and Office 2016 for Mac allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "GDI Information Disclosure Vulnerability."
Published 2016-12-20 · Modified
6.5EPSS 0.225
CVE-2010-3330
Microsoft Internet Explorer 6 through 8 does not properly restrict script access to content from a different (1) domain or (2) zone, which allows remote attackers to obtain sensitive information via a crafted web site, aka "Cross-Domain Information Disclosure Vulnerability."
Published 2010-10-13 · Modified
6.5EPSS 0.223
CVE-2016-7210
atmfd.dll in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted Open Type font on a web site, aka "Open Type Font Information Disclosure Vulnerability."
Published 2016-11-10 · Modified
6.5EPSS 0.211
CVE-2023-36563
Microsoft WordPad Information Disclosure Vulnerability
Published 2023-10-10 · Analyzed
6.5KEVEPSS 0.207
CVE-2026-20872
NTLM Hash Disclosure Spoofing Vulnerability
Published 2026-01-13 · Modified
6.5EPSS 0.201
CVE-2026-20925
NTLM Hash Disclosure Spoofing Vulnerability
Published 2026-01-13 · Analyzed
6.5EPSS 0.182
← Prev68 / 90Next →