VendorsMicrosoftwindows_server_2008sp2
Vulnerabilities

Microsoft Windows Server 2008 for 32-bit Systems sp2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

69CVEs
CVE-2009-3103
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via an & (ampersand) character in a Process ID High header field in a NEGOTIATE PROTOCOL REQUEST packet, which triggers an attempted dereference of an out-of-bounds memory location, aka "SMBv2 Negotiation Vulnerability." NOTE: some of these details are obtained from third party information.
Published 2009-09-08 · Modified
10.06 PoCEPSS 0.923
CVE-2009-2505
The Internet Authentication Service (IAS) in Microsoft Windows Vista SP2 and Server 2008 SP2 does not properly validate MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication requests, which allows remote attackers to execute arbitrary code via crafted structures in a malformed request, aka "Internet Authentication Service Memory Corruption Vulnerability."
Published 2009-12-09 · Modified
10.0EPSS 0.316
CVE-2021-26897
Windows DNS Server Remote Code Execution Vulnerability
Published 2021-03-11 · Modified
10.0EPSS 0.116
CVE-2021-26895
Windows DNS Server Remote Code Execution Vulnerability
Published 2021-03-11 · Modified
10.0EPSS 0.073
CVE-2021-26894
Windows DNS Server Remote Code Execution Vulnerability
Published 2021-03-11 · Modified
10.0EPSS 0.073
CVE-2022-26937
Windows Network File System Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
9.8EPSS 0.760
CVE-2023-36397
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Published 2023-11-14 · Modified
9.8EPSS 0.175
CVE-2022-22012
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
9.8EPSS 0.040
CVE-2021-31962
Kerberos AppContainer Security Feature Bypass Vulnerability
Published 2021-06-08 · Modified
9.8EPSS 0.038
CVE-2017-8759
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability."
Published 2017-09-13 · Analyzed
9.3KEV1 PoCEPSS 0.887
CVE-2013-3918
The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via a crafted web page that is accessed by Internet Explorer, as exploited in the wild in November 2013, aka "InformationCardSigninHelper Vulnerability."
Published 2013-11-12 · Analyzed
9.3KEV1 PoCEPSS 0.737
CVE-2022-23270
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
9.3EPSS 0.704
CVE-2018-8392
A buffer overflow vulnerability exists in the Microsoft JET Database Engine that could allow remote code execution on an affected system, aka "Microsoft JET Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8393.
Published 2018-09-13 · Modified
9.3EPSS 0.228
CVE-2018-8393
A buffer overflow vulnerability exists in the Microsoft JET Database Engine that could allow remote code execution on an affected system, aka "Microsoft JET Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8392.
Published 2018-09-13 · Modified
9.3EPSS 0.225
CVE-2021-31956
Windows NTFS Elevation of Privilege Vulnerability
Published 2021-06-08 · Analyzed
9.3KEVEPSS 0.223
CVE-2020-1046
.NET Framework Remote Code Execution Vulnerability
Published 2020-08-17 · Modified
9.3EPSS 0.038
CVE-2021-33742
Windows MSHTML Platform Remote Code Execution Vulnerability
Published 2021-06-08 · Analyzed
8.8KEVEPSS 0.594
CVE-2021-42282
Active Directory Domain Services Elevation of Privilege Vulnerability
Published 2021-11-10 · Modified
8.8EPSS 0.042
CVE-2022-22019
Remote Procedure Call Runtime Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
8.8EPSS 0.026
CVE-2021-31958
Windows NTLM Elevation of Privilege Vulnerability
Published 2021-06-08 · Modified
8.8EPSS 0.026
CVE-2022-22014
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
8.8EPSS 0.024
CVE-2022-22013
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
8.8EPSS 0.024
CVE-2021-31971
Windows HTML Platforms Security Feature Bypass Vulnerability
Published 2021-06-08 · Modified
8.8EPSS 0.021
CVE-2023-36402
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Published 2023-11-14 · Modified
8.8EPSS 0.018
CVE-2022-26829
Windows DNS Server Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
8.5EPSS 0.019
CVE-2024-49138
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Published 2024-12-10 · Analyzed
7.8KEV1 PoCEPSS 0.262
CVE-2022-29104
Windows Print Spooler Elevation of Privilege Vulnerability
Published 2022-05-10 · Modified
7.8EPSS 0.118
CVE-2022-21880
Windows GDI+ Information Disclosure Vulnerability
Published 2022-01-11 · Modified
7.8EPSS 0.039
CVE-2022-29105
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
7.8EPSS 0.027
CVE-2022-26926
Windows Address Book Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
7.8EPSS 0.027
CVE-2021-40465
Windows Text Shaping Remote Code Execution Vulnerability
Published 2021-10-13 · Modified
7.8EPSS 0.025
CVE-2022-29115
Windows Fax Service Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
7.8EPSS 0.023
CVE-2022-26929
.NET Framework Remote Code Execution Vulnerability
Published 2022-09-13 · Modified
7.8EPSS 0.016
CVE-2022-41089
.NET Framework Remote Code Execution Vulnerability
Published 2022-12-13 · Modified
7.8EPSS 0.012
CVE-2023-36393
Windows User Interface Application Core Remote Code Execution Vulnerability
Published 2023-11-14 · Modified
7.8EPSS 0.010
CVE-2021-26899
Windows UPnP Device Host Elevation of Privilege Vulnerability
Published 2021-03-11 · Modified
7.8EPSS 0.010
CVE-2021-26898
Windows Event Tracing Elevation of Privilege Vulnerability
Published 2021-03-11 · Modified
7.8EPSS 0.009
CVE-2021-28350
Windows GDI+ Remote Code Execution Vulnerability
Published 2021-04-13 · Modified
7.8EPSS 0.008
CVE-2021-26901
Windows Event Tracing Elevation of Privilege Vulnerability
Published 2021-03-11 · Modified
7.8EPSS 0.008
CVE-2021-28348
Windows GDI+ Remote Code Execution Vulnerability
Published 2021-04-13 · Modified
7.8EPSS 0.007
1 / 2Next →