Vulnerabilities > Perforce > Medium

DATE CVE VULNERABILITY TITLE RISK
2008-03-12 CVE-2008-1303 Improper Input Validation vulnerability in Perforce Server
The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of service (daemon crash) via a missing parameter to the (1) dm-FaultFile, (2) dm-LazyCheck, (3) dm-ResolvedFile, (4) dm-OpenFile, (5) crypto, and possibly unspecified other commands, which triggers a NULL pointer dereference.
network
low complexity
perforce CWE-20
5.0
2008-03-12 CVE-2008-1302 Numeric Errors vulnerability in Perforce Server
The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of service (daemon crash) via a (1) server-DiffFile or (2) server-ReleaseFile command with a large integer value, which is used in an array initialization calculation, and leads to invalid memory access.
network
low complexity
microsoft perforce CWE-189
5.0