Known vulnerabilities in Windows Server 2008 R2 SP1 - page 7

Vendor: Microsoft
Version: 2008 R2 SP1
Software CPE: cpe:2.3:o:microsoft:windows_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 470
Public exploits: 16
Known exploited (KEV): 25
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Windows Server version 2008 R2 SP1 Windows Server 2008 R2 SP1 is affected by 470 vulnerabilities: 7 critical, 142 high, 93 medium, 228 low Critical High Medium Low

Vulnerabilities (470)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU107993 - Heap-based Buffer Overflow
CVE-2025-26634
CWE-122 Medium
No
No
2008 R2 6.1.7601.27663, 2016 10.0.14393.7785, 2019 10.0.17763.6893, 2022 23H2 10.0.25398.1425, 2022 10.0.20348.3207, 2025 10.0.26100.3194 28.04.2025 SB20250311117
#VU105517 - Incorrect Conversion between Numeric Types
CVE-2025-24059
CWE-681 Low
No
No
2008 R2 6.1.7601.27618, 2008 6.0.6003.23168, 2012 R2 6.3.9600.22470, 2012 6.2.9200.25368, 2016 10.0.14393.7876, 2019 10.0.17763.7009, 2022 23H2 10.0.25398.1486, 2022 10.0.20348.3270, 2022 10.0.20348.3328, 2025 10.0.26100.3403, 2025 10.0.26100.3476 11.03.2025 SB2025031160
#VU105516 - Use After Free
CVE-2025-24983
CWE-416 High
No
Exploited
2008 R2 6.1.7601.27618, 2008 6.0.6003.23168, 2012 R2 6.3.9600.22470, 2012 6.2.9200.25368, 2016 10.0.14393.7876 11.03.2025 SB2025031159
#VU105514 - Heap-based Buffer Overflow
CVE-2025-24993
CWE-122 High
No
Exploited
2008 R2 6.1.7601.27618, 2008 6.0.6003.23168, 2012 R2 6.3.9600.22470, 2012 6.2.9200.25368, 2016 10.0.14393.7876, 2019 10.0.17763.7009, 2022 23H2 10.0.25398.1486, 2022 10.0.20348.3270, 2022 10.0.20348.3328, 2025 10.0.26100.3403, 2025 10.0.26100.3476 11.03.2025 SB2025031157
#VU105513 - Out-of-bounds read
CVE-2025-24991
CWE-125 High
No
Exploited
2008 R2 6.1.7601.27618, 2008 6.0.6003.23168, 2012 R2 6.3.9600.22470, 2012 6.2.9200.25368, 2016 10.0.14393.7876, 2019 10.0.17763.7009, 2022 23H2 10.0.25398.1486, 2022 10.0.20348.3270, 2022 10.0.20348.3328, 2025 10.0.26100.3403, 2025 10.0.26100.3476 11.03.2025 SB2025031156
#VU105512 - Integer overflow
CVE-2025-24985
CWE-190 High
No
Exploited
2008 R2 6.1.7601.27618, 2008 6.0.6003.23168, 2012 R2 6.3.9600.22470, 2012 6.2.9200.25368, 2016 10.0.14393.7876, 2019 10.0.17763.7009, 2022 23H2 10.0.25398.1486, 2022 10.0.20348.3270, 2022 10.0.20348.3328, 2025 10.0.26100.3403, 2025 10.0.26100.3476 11.03.2025 SB2025031155
#VU103826 - Improper Access Control
CVE-2025-21359
CWE-284 Low
No
No
2008 R2 6.1.7601.27566, 2008 6.0.6003.23117, 2012 R2 6.3.9600.22417, 2012 6.2.9200.25317, 2016 10.0.14393.7785, 2022 23H2 10.0.25398.1425, 2022 10.0.20348.3148, 2022 10.0.20348.3207, 2025 10.0.26100.3107, 2025 10.0.26100.3194 11.02.2025 SB20250211128
#VU103823 - Improper input validation
CVE-2025-21375
CWE-20 Low
No
No
2008 R2 6.1.7601.27566, 2008 6.0.6003.23117, 2012 R2 6.3.9600.22417, 2012 6.2.9200.25317, 2016 10.0.14393.7785, 2022 23H2 10.0.25398.1425, 2022 10.0.20348.3148, 2022 10.0.20348.3207, 2025 10.0.26100.3107, 2025 10.0.26100.3194 11.02.2025 SB20250211125
#VU103822 - Improper input validation
CVE-2025-21350
CWE-20 Medium
No
No
2008 R2 6.1.7601.27566, 2008 6.0.6003.23117, 2012 R2 6.3.9600.22417, 2012 6.2.9200.25317, 2016 10.0.14393.7785, 2022 23H2 10.0.25398.1425, 2022 10.0.20348.3148, 2022 10.0.20348.3207, 2025 10.0.26100.3107, 2025 10.0.26100.3194 11.02.2025 SB20250211124
#VU103819 - Improper Access Control
CVE-2025-21337
CWE-284 Low
No
No
2008 R2 6.1.7601.27566, 2008 6.0.6003.23117, 2012 R2 6.3.9600.22417, 2012 6.2.9200.25317, 2016 10.0.14393.7785, 2022 23H2 10.0.25398.1425, 2022 10.0.20348.3148, 2022 10.0.20348.3207 11.02.2025 SB20250211121
#VU103817 - Improper Link Resolution Before File Access ('Link Following')
CVE-2025-21373
CWE-59 Low
No
No
2008 R2 6.1.7601.27566, 2008 6.0.6003.23117, 2012 R2 6.3.9600.22417, 2012 6.2.9200.25317, 2016 10.0.14393.7785, 2022 23H2 10.0.25398.1425, 2022 10.0.20348.3148, 2022 10.0.20348.3207, 2025 10.0.26100.3107, 2025 10.0.26100.3194 11.02.2025 SB20250211119
#VU103816 - Heap-based Buffer Overflow
CVE-2025-21368
CWE-122 Medium
No
No
2008 R2 6.1.7601.27566, 2008 6.0.6003.23117, 2012 R2 6.3.9600.22417, 2012 6.2.9200.25317, 2016 10.0.14393.7785, 2022 23H2 10.0.25398.1425, 2022 10.0.20348.3148, 2022 10.0.20348.3207, 2025 10.0.26100.3107, 2025 10.0.26100.3194 11.02.2025 SB20250211118
#VU103815 - Heap-based Buffer Overflow
CVE-2025-21369
CWE-122 Medium
No
No
2008 R2 6.1.7601.27566, 2008 6.0.6003.23117, 2012 R2 6.3.9600.22417, 2012 6.2.9200.25317, 2016 10.0.14393.7785, 2022 23H2 10.0.25398.1425, 2022 10.0.20348.3148, 2022 10.0.20348.3207, 2025 10.0.26100.3107, 2025 10.0.26100.3194 11.02.2025 SB20250211118
#VU103813 - Resource exhaustion
CVE-2025-21181
CWE-400 Medium
No
No
2008 R2 6.1.7601.27566, 2008 6.0.6003.23117, 2012 R2 6.3.9600.22417, 2012 6.2.9200.25317, 2016 10.0.14393.7785, 2022 23H2 10.0.25398.1425, 2022 10.0.20348.3148, 2022 10.0.20348.3207, 2025 10.0.26100.3107, 2025 10.0.26100.3194 11.02.2025 SB20250211116
#VU103804 - Improper Link Resolution Before File Access ('Link Following')
CVE-2025-21419
CWE-59 Low
No
Exploited
2008 R2 6.1.7601.27566, 2012 R2 6.3.9600.22417, 2012 6.2.9200.25317, 2016 10.0.14393.7785, 2022 23H2 10.0.25398.1425, 2022 10.0.20348.3148, 2022 10.0.20348.3207, 2025 10.0.26100.3107, 2025 10.0.26100.3194 11.02.2025 SB20250211112
#VU103800 - Heap-based Buffer Overflow
CVE-2025-21410
CWE-122 High
No
No
2008 R2 6.1.7601.27566, 2008 6.0.6003.23117, 2012 R2 6.3.9600.22417, 2012 6.2.9200.25317, 2016 10.0.14393.7785, 2019 10.0.17763.6893, 2022 23H2 10.0.25398.1425, 2022 10.0.20348.3148, 2022 10.0.20348.3207, 2025 10.0.26100.3107, 2025 10.0.26100.3194 11.02.2025 SB20250211104
#VU103799 - Heap-based Buffer Overflow
CVE-2025-21208
CWE-122 High
No
No
2008 R2 6.1.7601.27566, 2008 6.0.6003.23117, 2012 R2 6.3.9600.22417, 2012 6.2.9200.25317, 2016 10.0.14393.7785, 2019 10.0.17763.6893, 2022 23H2 10.0.25398.1425, 2022 10.0.20348.3148, 2022 10.0.20348.3207, 2025 10.0.26100.3107, 2025 10.0.26100.3194 11.02.2025 SB20250211104
#VU103795 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-21376
CWE-362 High
No
No
2008 R2 6.1.7601.27566, 2008 6.0.6003.23117, 2012 R2 6.3.9600.22417, 2012 6.2.9200.25317, 2016 10.0.14393.7785, 2022 23H2 10.0.25398.1425, 2022 10.0.20348.3148, 2022 10.0.20348.3207, 2025 10.0.26100.3107, 2025 10.0.26100.3194 11.02.2025 SB20250211100
#VU103794 - Double Free
CVE-2025-21201
CWE-415 High
No
No
2008 R2 6.1.7601.27566, 2008 6.0.6003.23117, 2012 R2 6.3.9600.22417, 2012 6.2.9200.25317, 2016 10.0.14393.7785, 2022 23H2 10.0.25398.1425, 2022 10.0.20348.3148, 2022 10.0.20348.3207, 2025 10.0.26100.3107, 2025 10.0.26100.3194 11.02.2025 SB2025021199
#VU103785 - Heap-based Buffer Overflow
CVE-2025-21200
CWE-122 High
No
No
2008 R2 6.1.7601.27566, 2008 6.0.6003.23117, 2012 R2 6.3.9600.22417, 2012 6.2.9200.25317, 2016 10.0.14393.7785, 2022 23H2 10.0.25398.1425, 2022 10.0.20348.3148, 2022 10.0.20348.3207, 2025 10.0.26100.3107, 2025 10.0.26100.3194 11.02.2025 SB2025021195


Showing elements 121 - 140 out of 470