Known Vulnerabilities for products from Perforce

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Perforce".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-40261 json Not Provided 2026-04-15 2026-04-16
CVE-2026-40176 json Not Provided 2026-04-15 2026-04-16
CVE-2023-45849 json An arbitrary code execution which results in privilege escalation was discovered in Helix Core versions prior to 2023.2. Rep... 9.8 - CRITICAL 2023-11-08 2023-12-08
CVE-2023-45319 json In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the commit function was identif... 7.5 - HIGH 2023-11-08 2023-11-15
CVE-2023-35767 json In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was ident... 7.5 - HIGH 2023-11-08 2023-11-15
CVE-2023-5759 json In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the buffer was identified. Rep... 7.5 - HIGH 2023-11-08 2023-11-15
CVE-2022-2394 json Puppet Bolt prior to version 3.24.0 will print sensitive parameters when planning a run resulting in them potentially being l... 3.5 - LOW 2022-07-19 2023-06-30
CVE-2021-29997 json An issue was discovered in Wind River VxWorks 7 before 21.03. A specially crafted packet may lead to buffer over-read on IKE. 5.3 - MEDIUM 2021-04-13 2021-06-10
CVE-2021-28973 json The XML Import functionality of the Administration console in Perforce Helix ALM 2020.3.1 Build 22 accepts XML input data tha... 4.9 - MEDIUM 2021-04-13 2022-05-03
CVE-2018-1000147 json An exposure of sensitive information vulnerability exists in Jenkins Perforce Plugin version 1.3.36 and older in PerforcePass... 6.5 - MEDIUM 2018-04-05 2018-05-15
CVE-2015-8965 json Rogue Wave JViews before 8.8 patch 21 and 8.9 before patch 1 allows remote attackers to execute arbitrary Java code that exis... 9.8 - CRITICAL 2017-04-06 2022-07-23
CVE-2013-1410 json Perforce P4web 2011.1 and 2012.1 has multiple XSS vulnerabilities 6.1 - MEDIUM 2020-02-12 2020-02-14
CVE-2010-0935 json Perforce Server 2009.2 and earlier, when the protection table is empty, allows remote authenticated users to obtain super pri... 4.6 - MEDIUM 2010-03-05 2010-03-08
CVE-2010-0934 json The triggers functionality in Perforce Server 2008.1 allows remote authenticated users with super privileges to execute arbit... 7.1 - HIGH 2010-03-05 2010-03-08
CVE-2010-0933 json Directory traversal vulnerability in Perforce Server 2008.1 allows remote authenticated users to create arbitrary files via a... 6.8 - MEDIUM 2010-03-05 2012-06-15
CVE-2010-0932 json The FTP server in Perforce Server 2008.1 allows remote attackers to cause a denial of service (NULL pointer dereference and d... 5 - MEDIUM 2010-03-05 2010-03-08
CVE-2010-0931 json The Perforce service (p4s.exe) in Perforce Server 2008.1 allows remote attackers to cause a denial of service (daemon crash) ... 5 - MEDIUM 2010-03-05 2010-03-08
CVE-2010-0930 json The Perforce service (p4s.exe) in Perforce Server 2008.1 allows remote attackers to cause a denial of service (infinite loop)... 5 - MEDIUM 2010-03-05 2010-03-08
CVE-2010-0929 json The Perforce service (p4s.exe) in Perforce Server 2008.1 allows remote attackers to cause a denial of service (daemon crash) ... 5 - MEDIUM 2010-03-05 2010-03-08
CVE-2008-1338 json The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of serv... 7.8 - HIGH 2008-03-14 2018-10-11

Known software with vulnerabilities from Perforce

Type Vendor Product Version
ApplicationPerforceP4web2011.1