VendorsMicrosoftwindows_server_2008any version
Vulnerabilities

Microsoft Windows Server 2008 for 32-bit Systems any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3613CVEs
CVE-2019-1040
Windows NTLM Tampering Vulnerability
Published 2019-06-12 · Modified
5.9EPSS 0.480
CVE-2017-0271
Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0267, CVE-2017-0268, CVE-2017-0270, CVE-2017-0274, CVE-2017-0275, and CVE-2017-0276.
Published 2017-05-12 · Modified
5.9EPSS 0.133
CVE-2017-0267
Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0268, CVE-2017-0270, CVE-2017-0271, CVE-2017-0274, CVE-2017-0275, and CVE-2017-0276.
Published 2017-05-12 · Modified
5.9EPSS 0.127
CVE-2017-8582
HTTP.sys in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when the component improperly handles objects in memory, aka "Https.sys Information Disclosure Vulnerability".
Published 2017-07-11 · Modified
5.9EPSS 0.083
CVE-2017-0275
Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0267, CVE-2017-0268, CVE-2017-0270, CVE-2017-0271, CVE-2017-0274, and CVE-2017-0276.
Published 2017-05-12 · Modified
5.9EPSS 0.076
CVE-2017-0268
Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0267, CVE-2017-0270, CVE-2017-0271, CVE-2017-0274, CVE-2017-0275, and CVE-2017-0276.
Published 2017-05-12 · Modified
5.9EPSS 0.072
CVE-2017-0270
Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0267, CVE-2017-0268, CVE-2017-0271, CVE-2017-0274, CVE-2017-0275, and CVE-2017-0276.
Published 2017-05-12 · Modified
5.9EPSS 0.072
CVE-2017-0276
Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0267, CVE-2017-0268, CVE-2017-0270, CVE-2017-0271, CVE-2017-0274, and CVE-2017-0275.
Published 2017-05-12 · Modified
5.9EPSS 0.072
CVE-2017-0274
Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0267, CVE-2017-0268, CVE-2017-0270, CVE-2017-0271, CVE-2017-0275, and CVE-2017-0276.
Published 2017-05-12 · Modified
5.9EPSS 0.070
CVE-2017-0269
The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2017-0273 and CVE-2017-0280.
Published 2017-05-12 · Modified
5.9EPSS 0.065
CVE-2017-0273
The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2017-0269 and CVE-2017-0280.
Published 2017-05-12 · Modified
5.9EPSS 0.061
CVE-2019-0657
A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'.
Published 2019-03-06 · Modified
5.9EPSS 0.045
CVE-2017-0171
Windows DNS Server allows a denial of service vulnerability when Microsoft Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 Gold and R2, and Windows Server 2016 are configured to answer version queries, aka "Windows DNS Server Denial of Service Vulnerability".
Published 2017-05-12 · Modified
5.9EPSS 0.041
CVE-2019-1338
A security feature bypass vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLMv2 protection if a client is also sending LMv2 responses, aka 'Windows NTLM Security Feature Bypass Vulnerability'.
Published 2019-10-10 · Modified
5.9EPSS 0.036
CVE-2019-1318
A spoofing vulnerability exists when Transport Layer Security (TLS) accesses non- Extended Master Secret (EMS) sessions, aka 'Microsoft Windows Transport Layer Security Spoofing Vulnerability'.
Published 2019-10-10 · Modified
5.9EPSS 0.035
CVE-2019-0683
An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trusting forest request delegation of a TGT for an identity from the trusted forest, aka 'Active Directory Elevation of Privilege Vulnerability'.
Published 2019-04-08 · Modified
5.9EPSS 0.034
CVE-2021-33764
Windows Key Distribution Center Information Disclosure Vulnerability
Published 2021-07-14 · Modified
5.9EPSS 0.030
CVE-2022-22028
Windows Network File System Information Disclosure Vulnerability
Published 2022-07-12 · Modified
5.9EPSS 0.024
CVE-2025-21350
Windows Kerberos Denial of Service Vulnerability
Published 2025-02-11 · Analyzed
5.9EPSS 0.021
CVE-2022-35747
Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability
Published 2023-05-31 · Modified
5.9EPSS 0.017
CVE-2025-29954
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
Published 2025-05-13 · Analyzed
5.9EPSS 0.014
CVE-2024-38099
Windows Remote Desktop Licensing Service Denial of Service Vulnerability
Published 2024-07-09 · Modified
5.9EPSS 0.013
CVE-2025-27471
Microsoft Streaming Service Denial of Service Vulnerability
Published 2025-04-08 · Analyzed
5.9EPSS 0.013
CVE-2023-24900
Windows NTLM Security Support Provider Information Disclosure Vulnerability
Published 2023-05-09 · Modified
5.9EPSS 0.012
CVE-2019-13163
The Fujitsu TLS library allows a man-in-the-middle attack. This affects Interstage Application Development Cycle Manager V10 and other versions, Interstage Application Server V12 and other versions, Interstage Business Application Manager V2 and other versions, Interstage Information Integrator V11 and other versions, Interstage Job Workload Server V8, Interstage List Works V10 and other versions, Interstage Studio V12 and other versions, Interstage Web Server Express V11, Linkexpress V5, Safeauthor V3, ServerView Resource Orchestrator V3, Systemwalker Cloud Business Service Management V1, Systemwalker Desktop Keeper V15, Systemwalker Desktop Patrol V15, Systemwalker IT Change Manager V14, Systemwalker Operation Manager V16 and other versions, Systemwalker Runbook Automation V15 and other versions, Systemwalker Security Control V1, and Systemwalker Software Configuration Manager V15.
Published 2020-02-07 · Modified
5.9EPSS 0.006
CVE-2009-0233
The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not reuse cached DNS responses in all applicable situations, which makes it easier for remote attackers to predict transaction IDs and poison caches by simultaneously sending crafted DNS queries and responses, aka "DNS Server Query Validation Vulnerability."
Published 2009-03-11 · Modified
5.8EPSS 0.271
CVE-2011-1244
Microsoft Internet Explorer 6, 7, and 8 does not enforce intended domain restrictions on content access, which allows remote attackers to obtain sensitive information or conduct clickjacking attacks via a crafted web site, aka "Frame Tag Information Disclosure Vulnerability."
Published 2011-04-13 · Modified
5.8EPSS 0.151
CVE-2012-2549
The IP-HTTPS server in Windows Server 2008 R2 and R2 SP1 and Server 2012 does not properly validate certificates, which allows remote attackers to bypass intended access restrictions via a revoked certificate, aka "Revoked Certificate Bypass Vulnerability."
Published 2012-12-12 · Modified
5.8EPSS 0.100
CVE-2013-0013
The SSL provider component in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle encrypted packets, which allows man-in-the-middle attackers to conduct SSLv2 downgrade attacks against (1) SSLv3 sessions or (2) TLS sessions by intercepting handshakes and injecting content, aka "Microsoft SSL Version 3 and TLS Protocol Security Feature Bypass Vulnerability."
Published 2013-01-09 · Modified
5.8EPSS 0.064
CVE-2009-0089
Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Vista Gold allows remote web servers to impersonate arbitrary https web sites by using DNS spoofing to "forward a connection" to a different https web site that has a valid certificate matching its own domain name, but not a certificate matching the domain name of the host requested by the user, aka "Windows HTTP Services Certificate Name Mismatch Vulnerability."
Published 2009-04-15 · Modified
5.8EPSS 0.051
CVE-2019-0714
Windows Hyper-V Denial of Service Vulnerability
Published 2019-08-14 · Modified
5.8EPSS 0.050
CVE-2019-0715
Windows Hyper-V Denial of Service Vulnerability
Published 2019-08-14 · Modified
5.8EPSS 0.050
CVE-2015-6112
SChannel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 lacks the required extended master-secret binding support to ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-the-middle attackers to obtain sensitive information or modify TLS session data via a "triple handshake attack," aka "Schannel TLS Triple Handshake Vulnerability."
Published 2015-11-11 · Modified
5.8EPSS 0.028
CVE-2022-41064
.NET Framework Information Disclosure Vulnerability
Published 2022-11-09 · Modified
5.8EPSS 0.008
CVE-2021-1708
Windows GDI+ Information Disclosure Vulnerability
Published 2021-01-12 · Modified
5.7EPSS 0.034
CVE-2023-21693
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Published 2023-02-14 · Modified
5.7EPSS 0.014
CVE-2025-53719
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Published 2025-08-12 · Analyzed
5.7EPSS 0.013
CVE-2025-50156
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Published 2025-08-12 · Analyzed
5.7EPSS 0.012
CVE-2025-53148
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Published 2025-08-12 · Analyzed
5.7EPSS 0.012
CVE-2025-53153
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Published 2025-08-12 · Analyzed
5.7EPSS 0.012
← Prev75 / 91Next →