VendorsPerforceperforce_server2008.1
Vulnerabilities

Perforce Perforce Server 2008.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2010-0934
The triggers functionality in Perforce Server 2008.1 allows remote authenticated users with super privileges to execute arbitrary operating-system commands by using a "p4 client" command in conjunction with the form-in trigger script.
Published 2010-03-05 · Modified
7.1EPSS 0.020
CVE-2010-0933
Directory traversal vulnerability in Perforce Server 2008.1 allows remote authenticated users to create arbitrary files via a .. (dot dot) in the argument to the "p4 add" command.
Published 2010-03-05 · Modified
6.8EPSS 0.018
CVE-2010-0932
The FTP server in Perforce Server 2008.1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a certain MKD command.
Published 2010-03-05 · Modified
5.0EPSS 0.017
CVE-2010-0929
The Perforce service (p4s.exe) in Perforce Server 2008.1 allows remote attackers to cause a denial of service (daemon crash) via crafted data beginning with a byte sequence of 0x4c, 0xb3, 0xff, 0xff, and 0xff.
Published 2010-03-05 · Modified
5.0EPSS 0.011
CVE-2010-0930
The Perforce service (p4s.exe) in Perforce Server 2008.1 allows remote attackers to cause a denial of service (infinite loop) via crafted data that includes a byte sequence of 0xdc, 0xff, 0xff, and 0xff immediately before the client protocol version number.
Published 2010-03-05 · Modified
5.0EPSS 0.011
CVE-2010-0931
The Perforce service (p4s.exe) in Perforce Server 2008.1 allows remote attackers to cause a denial of service (daemon crash) via crafted data, possibly involving a large sndbuf value.
Published 2010-03-05 · Modified
5.0EPSS 0.011
CVE-2010-0935
Perforce Server 2009.2 and earlier, when the protection table is empty, allows remote authenticated users to obtain super privileges via a "p4 protect" command.
Published 2010-03-05 · Modified
4.6EPSS 0.016