Записи Perforce
31 опубликованных записей вендора perforce.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 38,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-400 Uncontrolled Resource Consumption6
- CWE-20 Improper Input Validation4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-611 Improper Restriction of XML External Entity Reference2
- CWE-399 Resource Management Errors2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
31 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2007-0100Эксплойта нет | The Perforce client does not restrict the set of files that it overwrites upon receiving a request from the server, which allows remote attaperforce · perforce client | Критическая10,0 | — | 1,9 % | 8 янв. 2007 г. |
40В плане | CVE-2015-8965Эксплойта нет | Rogue Wave JViews before 8.8 patch 21 and 8.9 before patch 1 allows remote attackers to execute arbitrary Java code that exists in the classperforce · jviews · CWE-264 | Критическая9,8 | — | 2,7 % | 6 апр. 2017 г. |
39Наблюдать | CVE-2023-45849Эксплойта нет | Arbitrary Code Execution in Helix Coreperforce · helix core · CWE-94 | Критическая9,8 | — | 1,1 % | 8 нояб. 2023 г. |
39Наблюдать | CVE-2024-3930Эксплойта нет | XML External Entity in Akanaperforce · akana api · CWE-611 | Критическая9,8 | — | 0,3 % | 30 июл. 2024 г. |
34Наблюдать | CVE-2024-10314Эксплойта нет | Unauthenticated Denial of Service via Auto Generation Functionhelix · helix core · CWE-400 | Высокая8,7 | — | 0,5 % | 11 нояб. 2024 г. |
34Наблюдать | CVE-2024-10345Эксплойта нет | Unauthenticated Denial of Service via Shutdown Functionhelix · helix core · CWE-400 | Высокая8,7 | — | 0,5 % | 11 нояб. 2024 г. |
34Наблюдать | CVE-2024-10344Эксплойта нет | Unauthenticated Denial of Service via Refuse Functionhelix · helix core · CWE-400 | Высокая8,7 | — | 0,5 % | 11 нояб. 2024 г. |
32Наблюдать | CVE-2008-1338Эксплойта нет | The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of service (daemon craperforce · perforce server · CWE-189 | Высокая7,8 | — | 2,1 % | 14 мар. 2008 г. |
32Наблюдать | CVE-2007-6349Эксплойта нет | P4Webs.exe in Perforce P4Web 2006.2 and earlier, when running on Windows, allows remote attackers to cause a denial of service (CPU consumptperforce · p4web · CWE-399 | Высокая7,8 | — | 2,0 % | 20 дек. 2007 г. |
31Наблюдать | CVE-2024-0325Эксплойта нет | Command Injection in Helix Syncperforce · helix sync · CWE-94 | Высокая7,8 | — | 0,8 % | 1 февр. 2024 г. |
30Наблюдать | CVE-2023-35767Эксплойта нет | Unauthenticated Remote Denial-of-Service via Shutdown Function in Helix Coreperforce · helix core · CWE-400 | Высокая7,5 | — | 0,9 % | 8 нояб. 2023 г. |
30Наблюдать | CVE-2023-5759Эксплойта нет | Unauthenticated Remote Denial-of-Service via Buffer in Helix Coreperforce · helix core · CWE-400 | Высокая7,5 | — | 0,9 % | 8 нояб. 2023 г. |
30Наблюдать | CVE-2023-45319Эксплойта нет | Unauthenticated Remote Denial-of-Service (Commit) in Helix Coreperforce · helix core · CWE-400 | Высокая7,5 | — | 0,9 % | 8 нояб. 2023 г. |
30Наблюдать | CVE-2024-5249Эксплойта нет | SAML Replay in Akanaperforce · akana api · CWE-294 | Высокая7,5 | — | 0,2 % | 30 июл. 2024 г. |
29Наблюдать | CVE-2010-0934Эксплойта нет | The triggers functionality in Perforce Server 2008.1 allows remote authenticated users with super privileges to execute arbitrary operating-perforce · perforce server · CWE-78 | Высокая7,1 | — | 2,0 % | 5 мар. 2010 г. |
28Наблюдать | CVE-2010-0933Эксплойта нет | Directory traversal vulnerability in Perforce Server 2008.1 allows remote authenticated users to create arbitrary files via a ..perforce · perforce server · CWE-22 | Средняя6,8 | — | 1,8 % | 5 мар. 2010 г. |
26Наблюдать | CVE-2018-1000147Эксплойта нет | An exposure of sensitive information vulnerability exists in Jenkins Perforce Plugin version 1.3.36 and older in PerforcePasswordEncryptor.jperforce · perforce · CWE-200 | Средняя6,5 | — | 0,8 % | 5 апр. 2018 г. |
24Наблюдать | CVE-2013-1410Proof of concept | Perforce P4web 2011.1 and 2012.1 has multiple XSS vulnerabilitiesperforce · p4web · CWE-79 | Средняя6,1 | — | 1,5 % | 12 февр. 2020 г. |
23Наблюдать | CVE-2024-8067Эксплойта нет | Unicode "best fit" argument injectionhelix · helix core · CWE-176 | Средняя5,8 | — | 0,2 % | 24 сент. 2024 г. |
22Наблюдать | CVE-2008-1303Proof of concept | The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of service (daemon craperforce · perforce server · CWE-20 | Средняя5,0 | — | 7,6 % | 12 мар. 2008 г. |
21Наблюдать | CVE-2008-1302Эксплойта нет | The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of service (daemon craperforce · perforce server · CWE-189 | Средняя5,0 | — | 1,7 % | 12 мар. 2008 г. |
21Наблюдать | CVE-2024-5250Эксплойта нет | Overly Verbose Errors in SAML Integrationperforce · akana api · CWE-209 | Средняя5,3 | — | 0,3 % | 30 июл. 2024 г. |
21Наблюдать | CVE-2025-14591Эксплойта нет | PII Leak Due to Change in EOR Handlingperforce · delphix continuous compliance · CWE-200 | Средняя5,3 | — | 0,3 % | 20 дек. 2025 г. |
20Наблюдать | CVE-2010-0932Эксплойта нет | The FTP server in Perforce Server 2008.1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) viperforce · perforce server · CWE-20 | Средняя5,0 | — | 1,7 % | 5 мар. 2010 г. |
20Наблюдать | CVE-2010-0929Эксплойта нет | The Perforce service (p4s.exe) in Perforce Server 2008.1 allows remote attackers to cause a denial of service (daemon crash) via crafted datperforce · perforce server · CWE-20 | Средняя5,0 | — | 1,1 % | 5 мар. 2010 г. |
- CVE-2007-010041В плане
The Perforce client does not restrict the set of files that it overwrites upon receiving a request from the server, which allows remote atta
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %perforce · perforce client8 янв. 2007 г.
- CVE-2015-896540В плане
Rogue Wave JViews before 8.8 patch 21 and 8.9 before patch 1 allows remote attackers to execute arbitrary Java code that exists in the class
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %perforce · jviews6 апр. 2017 г.
- CVE-2023-4584939Наблюдать
Arbitrary Code Execution in Helix Core
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %perforce · helix core8 нояб. 2023 г.
- CVE-2024-393039Наблюдать
XML External Entity in Akana
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %perforce · akana api30 июл. 2024 г.
- CVE-2024-1031434Наблюдать
Unauthenticated Denial of Service via Auto Generation Function
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %helix · helix core11 нояб. 2024 г.
- CVE-2024-1034534Наблюдать
Unauthenticated Denial of Service via Shutdown Function
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %helix · helix core11 нояб. 2024 г.
- CVE-2024-1034434Наблюдать
Unauthenticated Denial of Service via Refuse Function
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %helix · helix core11 нояб. 2024 г.
- CVE-2008-133832Наблюдать
The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of service (daemon cra
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %perforce · perforce server14 мар. 2008 г.
- CVE-2007-634932Наблюдать
P4Webs.exe in Perforce P4Web 2006.2 and earlier, when running on Windows, allows remote attackers to cause a denial of service (CPU consumpt
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %perforce · p4web20 дек. 2007 г.
- CVE-2024-032531Наблюдать
Command Injection in Helix Sync
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %perforce · helix sync1 февр. 2024 г.
- CVE-2023-3576730Наблюдать
Unauthenticated Remote Denial-of-Service via Shutdown Function in Helix Core
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %perforce · helix core8 нояб. 2023 г.
- CVE-2023-575930Наблюдать
Unauthenticated Remote Denial-of-Service via Buffer in Helix Core
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %perforce · helix core8 нояб. 2023 г.
- CVE-2023-4531930Наблюдать
Unauthenticated Remote Denial-of-Service (Commit) in Helix Core
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %perforce · helix core8 нояб. 2023 г.
- CVE-2024-524930Наблюдать
SAML Replay in Akana
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %perforce · akana api30 июл. 2024 г.
- CVE-2010-093429Наблюдать
The triggers functionality in Perforce Server 2008.1 allows remote authenticated users with super privileges to execute arbitrary operating-
ВысокаяCVSS 7,1Эксплойта нетEPSS 2 %perforce · perforce server5 мар. 2010 г.
- CVE-2010-093328Наблюдать
Directory traversal vulnerability in Perforce Server 2008.1 allows remote authenticated users to create arbitrary files via a ..
СредняяCVSS 6,8Эксплойта нетEPSS 2 %perforce · perforce server5 мар. 2010 г.
- CVE-2018-100014726Наблюдать
An exposure of sensitive information vulnerability exists in Jenkins Perforce Plugin version 1.3.36 and older in PerforcePasswordEncryptor.j
СредняяCVSS 6,5Эксплойта нетEPSS 1 %perforce · perforce5 апр. 2018 г.
- CVE-2013-141024Наблюдать
Perforce P4web 2011.1 and 2012.1 has multiple XSS vulnerabilities
СредняяCVSS 6,1Proof of conceptEPSS 2 %perforce · p4web12 февр. 2020 г.
- CVE-2024-806723Наблюдать
Unicode "best fit" argument injection
СредняяCVSS 5,8Эксплойта нетEPSS 0 %helix · helix core24 сент. 2024 г.
- CVE-2008-130322Наблюдать
The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of service (daemon cra
СредняяCVSS 5,0Proof of conceptEPSS 8 %perforce · perforce server12 мар. 2008 г.
- CVE-2008-130221Наблюдать
The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of service (daemon cra
СредняяCVSS 5,0Эксплойта нетEPSS 2 %perforce · perforce server12 мар. 2008 г.
- CVE-2024-525021Наблюдать
Overly Verbose Errors in SAML Integration
СредняяCVSS 5,3Эксплойта нетEPSS 0 %perforce · akana api30 июл. 2024 г.
- CVE-2025-1459121Наблюдать
PII Leak Due to Change in EOR Handling
СредняяCVSS 5,3Эксплойта нетEPSS 0 %perforce · delphix continuous compliance20 дек. 2025 г.
- CVE-2010-093220Наблюдать
The FTP server in Perforce Server 2008.1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) vi
СредняяCVSS 5,0Эксплойта нетEPSS 2 %perforce · perforce server5 мар. 2010 г.
- CVE-2010-092920Наблюдать
The Perforce service (p4s.exe) in Perforce Server 2008.1 allows remote attackers to cause a denial of service (daemon crash) via crafted dat
СредняяCVSS 5,0Эксплойта нетEPSS 1 %perforce · perforce server5 мар. 2010 г.