Vulnerabilities > Perforce > Perforce Server
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2010-03-05 | CVE-2010-0935 | Permissions, Privileges, and Access Controls vulnerability in Perforce Server Perforce Server 2009.2 and earlier, when the protection table is empty, allows remote authenticated users to obtain super privileges via a "p4 protect" command. | 4.6 |
2010-03-05 | CVE-2010-0934 | OS Command Injection vulnerability in Perforce Server 2008.1 The triggers functionality in Perforce Server 2008.1 allows remote authenticated users with super privileges to execute arbitrary operating-system commands by using a "p4 client" command in conjunction with the form-in trigger script. | 7.1 |
2010-03-05 | CVE-2010-0933 | Path Traversal vulnerability in Perforce Server 2008.1 Directory traversal vulnerability in Perforce Server 2008.1 allows remote authenticated users to create arbitrary files via a .. | 6.8 |
2010-03-05 | CVE-2010-0932 | Improper Input Validation vulnerability in Perforce Server 2008.1 The FTP server in Perforce Server 2008.1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a certain MKD command. | 5.0 |
2010-03-05 | CVE-2010-0931 | Improper Input Validation vulnerability in Perforce Server 2008.1 The Perforce service (p4s.exe) in Perforce Server 2008.1 allows remote attackers to cause a denial of service (daemon crash) via crafted data, possibly involving a large sndbuf value. | 5.0 |
2010-03-05 | CVE-2010-0930 | Resource Management Errors vulnerability in Perforce Server 2008.1 The Perforce service (p4s.exe) in Perforce Server 2008.1 allows remote attackers to cause a denial of service (infinite loop) via crafted data that includes a byte sequence of 0xdc, 0xff, 0xff, and 0xff immediately before the client protocol version number. | 5.0 |
2010-03-05 | CVE-2010-0929 | Improper Input Validation vulnerability in Perforce Server 2008.1 The Perforce service (p4s.exe) in Perforce Server 2008.1 allows remote attackers to cause a denial of service (daemon crash) via crafted data beginning with a byte sequence of 0x4c, 0xb3, 0xff, 0xff, and 0xff. | 5.0 |
2008-03-14 | CVE-2008-1338 | Numeric Errors vulnerability in Perforce Server The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of service (daemon crash) via a server-DiffFile command with an integer value within a certain range, which causes a loop until all memory is exhausted. | 7.8 |
2008-03-12 | CVE-2008-1303 | Improper Input Validation vulnerability in Perforce Server The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of service (daemon crash) via a missing parameter to the (1) dm-FaultFile, (2) dm-LazyCheck, (3) dm-ResolvedFile, (4) dm-OpenFile, (5) crypto, and possibly unspecified other commands, which triggers a NULL pointer dereference. | 5.0 |
2008-03-12 | CVE-2008-1302 | Numeric Errors vulnerability in Perforce Server The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of service (daemon crash) via a (1) server-DiffFile or (2) server-ReleaseFile command with a large integer value, which is used in an array initialization calculation, and leads to invalid memory access. | 5.0 |