VendorsMicrosoftwindows_server_2008any version
Vulnerabilities

Microsoft Windows Server 2008 for 32-bit Systems any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3613CVEs
CVE-2025-21255
Windows Digital Media Elevation of Privilege Vulnerability
Published 2025-01-14 · Analyzed
6.6EPSS 0.008
CVE-2025-21228
Windows Digital Media Elevation of Privilege Vulnerability
Published 2025-01-14 · Analyzed
6.6EPSS 0.008
CVE-2025-21256
Windows Digital Media Elevation of Privilege Vulnerability
Published 2025-01-14 · Analyzed
6.6EPSS 0.008
CVE-2025-21232
Windows Digital Media Elevation of Privilege Vulnerability
Published 2025-01-14 · Analyzed
6.6EPSS 0.008
CVE-2025-21310
Windows Digital Media Elevation of Privilege Vulnerability
Published 2025-01-14 · Analyzed
6.6EPSS 0.008
CVE-2025-21258
Windows Digital Media Elevation of Privilege Vulnerability
Published 2025-01-14 · Analyzed
6.6EPSS 0.008
CVE-2025-21249
Windows Digital Media Elevation of Privilege Vulnerability
Published 2025-01-14 · Analyzed
6.6EPSS 0.008
CVE-2025-21260
Windows Digital Media Elevation of Privilege Vulnerability
Published 2025-01-14 · Analyzed
6.6EPSS 0.008
CVE-2022-22048
BitLocker Security Feature Bypass Vulnerability
Published 2022-07-12 · Modified
6.6EPSS 0.008
CVE-2025-21327
Windows Digital Media Elevation of Privilege Vulnerability
Published 2025-01-14 · Analyzed
6.6EPSS 0.008
CVE-2025-21265
Windows Digital Media Elevation of Privilege Vulnerability
Published 2025-01-14 · Analyzed
6.6EPSS 0.008
CVE-2025-21263
Windows Digital Media Elevation of Privilege Vulnerability
Published 2025-01-14 · Analyzed
6.6EPSS 0.008
CVE-2025-21261
Windows Digital Media Elevation of Privilege Vulnerability
Published 2025-01-14 · Analyzed
6.6EPSS 0.008
CVE-2023-35344
Windows DNS Server Remote Code Execution Vulnerability
Published 2023-07-11 · Modified
6.6EPSS 0.007
CVE-2023-35345
Windows DNS Server Remote Code Execution Vulnerability
Published 2023-07-11 · Modified
6.6EPSS 0.007
CVE-2025-21341
Windows Digital Media Elevation of Privilege Vulnerability
Published 2025-01-14 · Analyzed
6.6EPSS 0.007
CVE-2023-35351
Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability
Published 2023-07-11 · Modified
6.6EPSS 0.007
CVE-2023-35346
Windows DNS Server Remote Code Execution Vulnerability
Published 2023-07-11 · Modified
6.6EPSS 0.007
CVE-2023-35310
Windows DNS Server Remote Code Execution Vulnerability
Published 2023-07-11 · Modified
6.6EPSS 0.007
CVE-2022-38032
Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability
Published 2022-10-11 · Modified
6.6EPSS 0.006
CVE-2024-43451
NTLM Hash Disclosure Spoofing Vulnerability
Published 2024-11-12 · Analyzed
6.5KEVEPSS 0.841
CVE-2019-1439
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
Published 2019-11-12 · Modified
6.5EPSS 0.754
CVE-2019-1252
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1286.
Published 2019-09-11 · Modified
6.5EPSS 0.604
CVE-2013-7331
The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC share pathnames, intranet hostnames, and intranet IP addresses by examining error codes, as demonstrated by a res:// URL, and exploited in the wild in February 2014.
Published 2014-02-26 · Analyzed
6.5KEVEPSS 0.502
CVE-2021-26414
Windows DCOM Server Security Feature Bypass
Published 2021-06-08 · Modified
6.5EPSS 0.498
CVE-2019-1009
Windows GDI Information Disclosure Vulnerability
Published 2019-06-12 · Modified
6.5EPSS 0.485
CVE-2016-0168
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to obtain sensitive information via a crafted document, aka "Windows Graphics Component Information Disclosure Vulnerability," a different vulnerability than CVE-2016-0169.
Published 2016-05-11 · Modified
6.51 PoCEPSS 0.432
CVE-2016-0169
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to obtain sensitive information via a crafted document, aka "Windows Graphics Component Information Disclosure Vulnerability," a different vulnerability than CVE-2016-0168.
Published 2016-05-11 · Modified
6.51 PoCEPSS 0.432
CVE-2025-21377
NTLM Hash Disclosure Spoofing Vulnerability
Published 2025-02-11 · Analyzed
6.5EPSS 0.399
CVE-2017-0063
The Color Management Module (ICM32.dll) memory handling functionality in Windows Vista SP2; Windows Server 2008 SP2 and R2; and Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to bypass ASLR and execute code in combination with another vulnerability through a crafted website, aka "Microsoft Color Management Information Disclosure Vulnerability." This vulnerability is different from that described in CVE-2017-0061.
Published 2017-03-17 · Modified
6.51 PoCEPSS 0.353
CVE-2015-0071
Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."
Published 2015-02-11 · Analyzed
6.5KEVEPSS 0.336
CVE-2016-3298
Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow remote attackers to determine the existence of arbitrary files via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."
Published 2016-10-14 · Analyzed
6.5KEVEPSS 0.333
CVE-2022-24502
Windows HTML Platforms Security Feature Bypass Vulnerability
Published 2022-03-09 · Modified
6.5EPSS 0.331
CVE-2025-50154
Microsoft Windows File Explorer Spoofing Vulnerability
Published 2025-08-12 · Modified
6.51 PoCEPSS 0.302
CVE-2010-0488
Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding strings," which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site, aka "Post Encoding Information Disclosure Vulnerability."
Published 2010-03-31 · Modified
6.5EPSS 0.292
CVE-2008-3474
Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy and obtain sensitive information via a crafted HTML document, aka "Cross-Domain Information Disclosure Vulnerability."
Published 2008-10-15 · Modified
6.5EPSS 0.280
CVE-2016-3351
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
Published 2016-09-14 · Analyzed
6.5KEVEPSS 0.263
CVE-2016-7257
The GDI component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office for Mac 2011, and Office 2016 for Mac allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "GDI Information Disclosure Vulnerability."
Published 2016-12-20 · Modified
6.5EPSS 0.225
CVE-2010-3330
Microsoft Internet Explorer 6 through 8 does not properly restrict script access to content from a different (1) domain or (2) zone, which allows remote attackers to obtain sensitive information via a crafted web site, aka "Cross-Domain Information Disclosure Vulnerability."
Published 2010-10-13 · Modified
6.5EPSS 0.223
CVE-2016-7210
atmfd.dll in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted Open Type font on a web site, aka "Open Type Font Information Disclosure Vulnerability."
Published 2016-11-10 · Modified
6.5EPSS 0.211
← Prev69 / 91Next →