Known Vulnerabilities for products from Perforce
Listed below are 17 of the newest known vulnerabilities associated with the vendor "Perforce".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-29997 | An issue was discovered in Wind River VxWorks 7 before 21.03. A specially crafted packet may lead to buffer over-read on IKE. | 5.3 - MEDIUM | 2021-04-13 | 2021-06-10 |
| CVE-2021-28973 | The XML Import functionality of the Administration console in Perforce Helix ALM 2020.3.1 Build 22 accepts XML input data tha... | 4.9 - MEDIUM | 2021-04-13 | 2022-05-03 |
| CVE-2018-1000147 | An exposure of sensitive information vulnerability exists in Jenkins Perforce Plugin version 1.3.36 and older in PerforcePass... | 6.5 - MEDIUM | 2018-04-05 | 2018-05-15 |
| CVE-2015-8965 | Rogue Wave JViews before 8.8 patch 21 and 8.9 before patch 1 allows remote attackers to execute arbitrary Java code that exis... | 9.8 - CRITICAL | 2017-04-06 | 2022-07-23 |
| CVE-2013-1410 | Perforce P4web 2011.1 and 2012.1 has multiple XSS vulnerabilities | 6.1 - MEDIUM | 2020-02-12 | 2020-02-14 |
| CVE-2010-0935 | Perforce Server 2009.2 and earlier, when the protection table is empty, allows remote authenticated users to obtain super pri... | 4.6 - MEDIUM | 2010-03-05 | 2010-03-08 |
| CVE-2010-0934 | The triggers functionality in Perforce Server 2008.1 allows remote authenticated users with super privileges to execute arbit... | 7.1 - HIGH | 2010-03-05 | 2010-03-08 |
| CVE-2010-0933 | Directory traversal vulnerability in Perforce Server 2008.1 allows remote authenticated users to create arbitrary files via a... | 6.8 - MEDIUM | 2010-03-05 | 2012-06-15 |
| CVE-2010-0932 | The FTP server in Perforce Server 2008.1 allows remote attackers to cause a denial of service (NULL pointer dereference and d... | 5 - MEDIUM | 2010-03-05 | 2010-03-08 |
| CVE-2010-0931 | The Perforce service (p4s.exe) in Perforce Server 2008.1 allows remote attackers to cause a denial of service (daemon crash) ... | 5 - MEDIUM | 2010-03-05 | 2010-03-08 |
| CVE-2010-0930 | The Perforce service (p4s.exe) in Perforce Server 2008.1 allows remote attackers to cause a denial of service (infinite loop)... | 5 - MEDIUM | 2010-03-05 | 2010-03-08 |
| CVE-2010-0929 | The Perforce service (p4s.exe) in Perforce Server 2008.1 allows remote attackers to cause a denial of service (daemon crash) ... | 5 - MEDIUM | 2010-03-05 | 2010-03-08 |
| CVE-2008-1338 | The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of serv... | 7.8 - HIGH | 2008-03-14 | 2018-10-11 |
| CVE-2008-1303 | The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of serv... | 5 - MEDIUM | 2008-03-12 | 2018-10-11 |
| CVE-2008-1302 | The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of serv... | 5 - MEDIUM | 2008-03-12 | 2018-10-11 |
| CVE-2007-6349 | P4Webs.exe in Perforce P4Web 2006.2 and earlier, when running on Windows, allows remote attackers to cause a denial of servic... | 7.8 - HIGH | 2007-12-20 | 2018-10-15 |
| CVE-2007-0100 | The Perforce client does not restrict the set of files that it overwrites upon receiving a request from the server, which all... | 10 - HIGH | 2007-01-08 | 2018-10-16 |
Known software with vulnerabilities from Perforce
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Perforce | P4web | 2011.1 |