Perforce records
31 published records for vendor perforce.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 38.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-400 Uncontrolled Resource Consumption6
- CWE-20 Improper Input Validation4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-611 Improper Restriction of XML External Entity Reference2
- CWE-399 Resource Management Errors2
The weakness classes this vendor ships most often: where to look.
CWEAll records
31 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2007-0100No exploit | The Perforce client does not restrict the set of files that it overwrites upon receiving a request from the server, which allows remote attaperforce · perforce client | Critical10.0 | — | 1.9% | Jan 8, 2007 |
40Plan | CVE-2015-8965No exploit | Rogue Wave JViews before 8.8 patch 21 and 8.9 before patch 1 allows remote attackers to execute arbitrary Java code that exists in the classperforce · jviews · CWE-264 | Critical9.8 | — | 2.7% | Apr 6, 2017 |
39Monitor | CVE-2023-45849No exploit | Arbitrary Code Execution in Helix Coreperforce · helix core · CWE-94 | Critical9.8 | — | 1.1% | Nov 8, 2023 |
39Monitor | CVE-2024-3930No exploit | XML External Entity in Akanaperforce · akana api · CWE-611 | Critical9.8 | — | 0.3% | Jul 30, 2024 |
34Monitor | CVE-2024-10314No exploit | Unauthenticated Denial of Service via Auto Generation Functionhelix · helix core · CWE-400 | High8.7 | — | 0.5% | Nov 11, 2024 |
34Monitor | CVE-2024-10345No exploit | Unauthenticated Denial of Service via Shutdown Functionhelix · helix core · CWE-400 | High8.7 | — | 0.5% | Nov 11, 2024 |
34Monitor | CVE-2024-10344No exploit | Unauthenticated Denial of Service via Refuse Functionhelix · helix core · CWE-400 | High8.7 | — | 0.5% | Nov 11, 2024 |
32Monitor | CVE-2008-1338No exploit | The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of service (daemon craperforce · perforce server · CWE-189 | High7.8 | — | 2.1% | Mar 14, 2008 |
32Monitor | CVE-2007-6349No exploit | P4Webs.exe in Perforce P4Web 2006.2 and earlier, when running on Windows, allows remote attackers to cause a denial of service (CPU consumptperforce · p4web · CWE-399 | High7.8 | — | 2.0% | Dec 20, 2007 |
31Monitor | CVE-2024-0325No exploit | Command Injection in Helix Syncperforce · helix sync · CWE-94 | High7.8 | — | 0.8% | Feb 1, 2024 |
30Monitor | CVE-2023-35767No exploit | Unauthenticated Remote Denial-of-Service via Shutdown Function in Helix Coreperforce · helix core · CWE-400 | High7.5 | — | 0.9% | Nov 8, 2023 |
30Monitor | CVE-2023-5759No exploit | Unauthenticated Remote Denial-of-Service via Buffer in Helix Coreperforce · helix core · CWE-400 | High7.5 | — | 0.9% | Nov 8, 2023 |
30Monitor | CVE-2023-45319No exploit | Unauthenticated Remote Denial-of-Service (Commit) in Helix Coreperforce · helix core · CWE-400 | High7.5 | — | 0.9% | Nov 8, 2023 |
30Monitor | CVE-2024-5249No exploit | SAML Replay in Akanaperforce · akana api · CWE-294 | High7.5 | — | 0.2% | Jul 30, 2024 |
29Monitor | CVE-2010-0934No exploit | The triggers functionality in Perforce Server 2008.1 allows remote authenticated users with super privileges to execute arbitrary operating-perforce · perforce server · CWE-78 | High7.1 | — | 2.0% | Mar 5, 2010 |
28Monitor | CVE-2010-0933No exploit | Directory traversal vulnerability in Perforce Server 2008.1 allows remote authenticated users to create arbitrary files via a ..perforce · perforce server · CWE-22 | Medium6.8 | — | 1.8% | Mar 5, 2010 |
26Monitor | CVE-2018-1000147No exploit | An exposure of sensitive information vulnerability exists in Jenkins Perforce Plugin version 1.3.36 and older in PerforcePasswordEncryptor.jperforce · perforce · CWE-200 | Medium6.5 | — | 0.8% | Apr 5, 2018 |
24Monitor | CVE-2013-1410Proof of concept | Perforce P4web 2011.1 and 2012.1 has multiple XSS vulnerabilitiesperforce · p4web · CWE-79 | Medium6.1 | — | 1.5% | Feb 12, 2020 |
23Monitor | CVE-2024-8067No exploit | Unicode "best fit" argument injectionhelix · helix core · CWE-176 | Medium5.8 | — | 0.2% | Sep 24, 2024 |
22Monitor | CVE-2008-1303Proof of concept | The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of service (daemon craperforce · perforce server · CWE-20 | Medium5.0 | — | 7.6% | Mar 12, 2008 |
21Monitor | CVE-2008-1302No exploit | The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of service (daemon craperforce · perforce server · CWE-189 | Medium5.0 | — | 1.7% | Mar 12, 2008 |
21Monitor | CVE-2024-5250No exploit | Overly Verbose Errors in SAML Integrationperforce · akana api · CWE-209 | Medium5.3 | — | 0.3% | Jul 30, 2024 |
21Monitor | CVE-2025-14591No exploit | PII Leak Due to Change in EOR Handlingperforce · delphix continuous compliance · CWE-200 | Medium5.3 | — | 0.3% | Dec 20, 2025 |
20Monitor | CVE-2010-0932No exploit | The FTP server in Perforce Server 2008.1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) viperforce · perforce server · CWE-20 | Medium5.0 | — | 1.7% | Mar 5, 2010 |
20Monitor | CVE-2010-0929No exploit | The Perforce service (p4s.exe) in Perforce Server 2008.1 allows remote attackers to cause a denial of service (daemon crash) via crafted datperforce · perforce server · CWE-20 | Medium5.0 | — | 1.1% | Mar 5, 2010 |
- CVE-2007-010041Plan
The Perforce client does not restrict the set of files that it overwrites upon receiving a request from the server, which allows remote atta
CriticalCVSS 10.0No exploitEPSS 2%perforce · perforce clientJan 8, 2007
- CVE-2015-896540Plan
Rogue Wave JViews before 8.8 patch 21 and 8.9 before patch 1 allows remote attackers to execute arbitrary Java code that exists in the class
CriticalCVSS 9.8No exploitEPSS 3%perforce · jviewsApr 6, 2017
- CVE-2023-4584939Monitor
Arbitrary Code Execution in Helix Core
CriticalCVSS 9.8No exploitEPSS 1%perforce · helix coreNov 8, 2023
- CVE-2024-393039Monitor
XML External Entity in Akana
CriticalCVSS 9.8No exploitEPSS 0%perforce · akana apiJul 30, 2024
- CVE-2024-1031434Monitor
Unauthenticated Denial of Service via Auto Generation Function
HighCVSS 8.7No exploitEPSS 0%helix · helix coreNov 11, 2024
- CVE-2024-1034534Monitor
Unauthenticated Denial of Service via Shutdown Function
HighCVSS 8.7No exploitEPSS 0%helix · helix coreNov 11, 2024
- CVE-2024-1034434Monitor
Unauthenticated Denial of Service via Refuse Function
HighCVSS 8.7No exploitEPSS 0%helix · helix coreNov 11, 2024
- CVE-2008-133832Monitor
The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of service (daemon cra
HighCVSS 7.8No exploitEPSS 2%perforce · perforce serverMar 14, 2008
- CVE-2007-634932Monitor
P4Webs.exe in Perforce P4Web 2006.2 and earlier, when running on Windows, allows remote attackers to cause a denial of service (CPU consumpt
HighCVSS 7.8No exploitEPSS 2%perforce · p4webDec 20, 2007
- CVE-2024-032531Monitor
Command Injection in Helix Sync
HighCVSS 7.8No exploitEPSS 1%perforce · helix syncFeb 1, 2024
- CVE-2023-3576730Monitor
Unauthenticated Remote Denial-of-Service via Shutdown Function in Helix Core
HighCVSS 7.5No exploitEPSS 1%perforce · helix coreNov 8, 2023
- CVE-2023-575930Monitor
Unauthenticated Remote Denial-of-Service via Buffer in Helix Core
HighCVSS 7.5No exploitEPSS 1%perforce · helix coreNov 8, 2023
- CVE-2023-4531930Monitor
Unauthenticated Remote Denial-of-Service (Commit) in Helix Core
HighCVSS 7.5No exploitEPSS 1%perforce · helix coreNov 8, 2023
- CVE-2024-524930Monitor
SAML Replay in Akana
HighCVSS 7.5No exploitEPSS 0%perforce · akana apiJul 30, 2024
- CVE-2010-093429Monitor
The triggers functionality in Perforce Server 2008.1 allows remote authenticated users with super privileges to execute arbitrary operating-
HighCVSS 7.1No exploitEPSS 2%perforce · perforce serverMar 5, 2010
- CVE-2010-093328Monitor
Directory traversal vulnerability in Perforce Server 2008.1 allows remote authenticated users to create arbitrary files via a ..
MediumCVSS 6.8No exploitEPSS 2%perforce · perforce serverMar 5, 2010
- CVE-2018-100014726Monitor
An exposure of sensitive information vulnerability exists in Jenkins Perforce Plugin version 1.3.36 and older in PerforcePasswordEncryptor.j
MediumCVSS 6.5No exploitEPSS 1%perforce · perforceApr 5, 2018
- CVE-2013-141024Monitor
Perforce P4web 2011.1 and 2012.1 has multiple XSS vulnerabilities
MediumCVSS 6.1Proof of conceptEPSS 2%perforce · p4webFeb 12, 2020
- CVE-2024-806723Monitor
Unicode "best fit" argument injection
MediumCVSS 5.8No exploitEPSS 0%helix · helix coreSep 24, 2024
- CVE-2008-130322Monitor
The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of service (daemon cra
MediumCVSS 5.0Proof of conceptEPSS 8%perforce · perforce serverMar 12, 2008
- CVE-2008-130221Monitor
The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of service (daemon cra
MediumCVSS 5.0No exploitEPSS 2%perforce · perforce serverMar 12, 2008
- CVE-2024-525021Monitor
Overly Verbose Errors in SAML Integration
MediumCVSS 5.3No exploitEPSS 0%perforce · akana apiJul 30, 2024
- CVE-2025-1459121Monitor
PII Leak Due to Change in EOR Handling
MediumCVSS 5.3No exploitEPSS 0%perforce · delphix continuous complianceDec 20, 2025
- CVE-2010-093220Monitor
The FTP server in Perforce Server 2008.1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) vi
MediumCVSS 5.0No exploitEPSS 2%perforce · perforce serverMar 5, 2010
- CVE-2010-092920Monitor
The Perforce service (p4s.exe) in Perforce Server 2008.1 allows remote attackers to cause a denial of service (daemon crash) via crafted dat
MediumCVSS 5.0No exploitEPSS 1%perforce · perforce serverMar 5, 2010