Known vulnerabilities in Windows Server 2008 R2 SP1 - page 2

Vendor: Microsoft
Version: 2008 R2 SP1
Software CPE: cpe:2.3:o:microsoft:windows_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 470
Public exploits: 16
Known exploited (KEV): 25
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Windows Server version 2008 R2 SP1 Windows Server 2008 R2 SP1 is affected by 470 vulnerabilities: 7 critical, 142 high, 93 medium, 228 low Critical High Medium Low

Vulnerabilities (470)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU119450 - Use After Free
CVE-2025-62569
CWE-416 Low
No
No
2008 6.0.6003.23666, 2022 23H2 10.0.25398.2025, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120959
#VU119449 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-62469
CWE-362 Low
No
No
2008 6.0.6003.23666, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120959
#VU119442 - Out-of-bounds read
CVE-2025-62468
CWE-125 Low
No
No
2008 6.0.6003.23666, 2022 23H2 10.0.25398.2025, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120954
#VU119439 - Use After Free
CVE-2025-62573
CWE-416 Low
No
No
2008 6.0.6003.23666, 2016 10.0.14393.8688, 2019 10.0.17763.8146, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120950
#VU119437 - NULL Pointer Dereference
CVE-2025-62463
CWE-476 Low
No
No
2008 6.0.6003.23666, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120950
#VU119436 - NULL Pointer Dereference
CVE-2025-62465
CWE-476 Low
No
No
2008 6.0.6003.23666, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120950
#VU119434 - Integer overflow
CVE-2025-62467
CWE-190 Low
No
No
2008 6.0.6003.23666, 2019 10.0.17763.8146, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120948
#VU119433 - Out-of-bounds read
CVE-2025-55233
CWE-125 Low
No
No
2008 6.0.6003.23666, 2019 10.0.17763.8146, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120948
#VU119432 - Out-of-bounds read
CVE-2025-62464
CWE-125 Low
No
No
2008 6.0.6003.23666, 2019 10.0.17763.8146, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120948
#VU119431 - Use After Free
CVE-2025-62221
CWE-416 High
No
Exploited
2008 6.0.6003.23666, 2019 10.0.17763.8146, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120947
#VU118317 - Untrusted Pointer Dereference
CVE-2025-60708
CWE-822 Low
No
No
2008 R2 6.1.7601.28021, 2016 10.0.14393.8594, 2019 10.0.17763.8027, 2022 23H2 10.0.25398.1965, 2022 10.0.20348.4346, 2022 10.0.20348.4405, 2025 10.0.26100.7092, 2025 10.0.26100.7171 11.11.2025 SB2025111188
#VU118313 - Use After Free
CVE-2025-60707
CWE-416 Low
No
No
2008 R2 6.1.7601.28021, 2019 10.0.17763.8027, 2022 23H2 10.0.25398.1965, 2022 10.0.20348.4346, 2022 10.0.20348.4405, 2025 10.0.26100.7092, 2025 10.0.26100.7171 11.11.2025 SB2025111177
#VU118302 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-62215
CWE-362 High
Public exploit available
Exploited
2008 R2 6.1.7601.28021, 2019 10.0.17763.8027, 2022 23H2 10.0.25398.1965, 2022 10.0.20348.4346, 2022 10.0.20348.4405, 2025 10.0.26100.7092, 2025 10.0.26100.7171 11.11.2025 SB2025111168
#VU118296 - Out-of-bounds read
CVE-2025-60706
CWE-125 Low
No
No
2008 R2 6.1.7601.28021, 2016 10.0.14393.8594, 2019 10.0.17763.8027, 2022 23H2 10.0.25398.1965, 2022 10.0.20348.4346, 2022 10.0.20348.4405, 2025 10.0.26100.7092, 2025 10.0.26100.7171 11.11.2025 SB2025111163
#VU118295 - Use After Free
CVE-2025-60717
CWE-416 Low
No
No
2008 R2 6.1.7601.28021, 2019 10.0.17763.8027, 2022 23H2 10.0.25398.1965, 2025 10.0.26100.7092, 2025 10.0.26100.7171 11.11.2025 SB2025111162
#VU118294 - Use After Free
CVE-2025-59515
CWE-416 Low
No
No
2008 R2 6.1.7601.28021, 2019 10.0.17763.8027, 2022 23H2 10.0.25398.1965, 2025 10.0.26100.7092, 2025 10.0.26100.7171 11.11.2025 SB2025111162
#VU118287 - Information Exposure Through Log Files
CVE-2025-62209
CWE-532 Low
No
No
2008 R2 6.1.7601.28021, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 11.11.2025 SB2025111156
#VU118286 - Information Exposure Through Log Files
CVE-2025-62208
CWE-532 Low
No
No
2008 R2 6.1.7601.28021, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 11.11.2025 SB2025111156
#VU118280 - Untrusted Pointer Dereference
CVE-2025-60713
CWE-822 Low
No
No
2008 R2 6.1.7601.28021, 2016 10.0.14393.8594, 2019 10.0.17763.8027, 2022 23H2 10.0.25398.1965, 2022 10.0.20348.4346, 2022 10.0.20348.4405, 2025 10.0.26100.7092, 2025 10.0.26100.7171 11.11.2025 SB2025111152
#VU118275 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-60723
CWE-362 Medium
No
No
2008 R2 6.1.7601.28021, 2019 10.0.17763.8027, 2022 23H2 10.0.25398.1965, 2022 10.0.20348.4346, 2022 10.0.20348.4405, 2025 10.0.26100.7092, 2025 10.0.26100.7171 11.11.2025 SB2025111150


Showing elements 21 - 40 out of 470