Perforce Server
Vendor:
First CVE: Mar 12, 2008 · Active for 18 years
10
Total CVEs
More Total CVEs than 88% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
5.6
Avg CVSS
Higher Avg CVSS than 16% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Perforce Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 12, 2008
18 years ago
Most Recent CVE
Mar 5, 2010
5,985 days ago
CVE Severity & Scoring
Perforce Server10 CVEs
80%
20%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown10 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown10 (100.0%)
User Interaction
None0 (0.0%)
Unknown10 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown10 (100.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-1303MEDIUM The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of service (daemon crash) via a missing parameter to the (1) d | Mar 12, 2008 | 5.0 | 27 | NO | YES |
CVE-2008-1338HIGH The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of service (daemon crash) via a server-DiffFile command with a | Mar 14, 2008 | 7.8 | 22 | NO | NO |
CVE-2010-0934HIGH The triggers functionality in Perforce Server 2008.1 allows remote authenticated users with super privileges to execute arbitrary operating-system commands by using a "p4 client" c | Mar 5, 2010 | 7.1 | 20 | NO | NO |
CVE-2010-0933MEDIUM Directory traversal vulnerability in Perforce Server 2008.1 allows remote authenticated users to create arbitrary files via a .. (dot dot) in the argument to the "p4 add" command. | Mar 5, 2010 | 6.8 | 18 | NO | NO |
CVE-2010-0935MEDIUM Perforce Server 2009.2 and earlier, when the protection table is empty, allows remote authenticated users to obtain super privileges via a "p4 protect" command. | Mar 5, 2010 | 4.6 | 16 | NO | NO |
CVE-2008-1302MEDIUM The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of service (daemon crash) via a (1) server-DiffFile or (2) ser | Mar 12, 2008 | 5.0 | 16 | NO | NO |
CVE-2010-0932MEDIUM The FTP server in Perforce Server 2008.1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a certain MKD command. | Mar 5, 2010 | 5.0 | 15 | NO | NO |
CVE-2010-0931MEDIUM The Perforce service (p4s.exe) in Perforce Server 2008.1 allows remote attackers to cause a denial of service (daemon crash) via crafted data, possibly involving a large sndbuf val | Mar 5, 2010 | 5.0 | 15 | NO | NO |
CVE-2010-0930MEDIUM The Perforce service (p4s.exe) in Perforce Server 2008.1 allows remote attackers to cause a denial of service (infinite loop) via crafted data that includes a byte sequence of 0xdc | Mar 5, 2010 | 5.0 | 15 | NO | NO |
CVE-2010-0929MEDIUM The Perforce service (p4s.exe) in Perforce Server 2008.1 allows remote attackers to cause a denial of service (daemon crash) via crafted data beginning with a byte sequence of 0x4c | Mar 5, 2010 | 5.0 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
10.0% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Perforce Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 99.2 | 1 | 4.6 | 1.6% | 0 | 0 |
| 99.1 | 1 | 4.6 | 1.6% | 0 | 0 |
| 98.2 | 1 | 4.6 | 1.6% | 0 | 0 |
| 97.3 | 1 | 4.6 | 1.6% | 0 | 0 |
| 2008.2 | 1 | 4.6 | 1.6% | 0 | 0 |
| 2008.1 | 7 | 5.5 | 1.5% | 0 | 0 |
| 2007.3_143793 | 1 | 4.6 | 1.6% | 0 | 0 |
| 2007.3 | 2 | 4.8 | 4.6% | 0 | 1 |
| 2007.2 | 2 | 4.8 | 4.6% | 0 | 1 |
| 2006.2 | 2 | 4.8 | 4.6% | 0 | 1 |
| 2006.1 | 2 | 4.8 | 4.6% | 0 | 1 |
| 2005.2 | 2 | 4.8 | 4.6% | 0 | 1 |
| 2005.1 | 2 | 4.8 | 4.6% | 0 | 1 |
| 2004.2 | 2 | 4.8 | 4.6% | 0 | 1 |
| 2003.2 | 2 | 4.8 | 4.6% | 0 | 1 |
| 2003.1 | 2 | 4.8 | 4.6% | 0 | 1 |
| 2002.2 | 2 | 4.8 | 4.6% | 0 | 1 |
| 2002.1 | 2 | 4.8 | 4.6% | 0 | 1 |
| 2001.2 | 2 | 4.8 | 4.6% | 0 | 1 |
| 2001.1 | 2 | 4.8 | 4.6% | 0 | 1 |