CVE-2026-103510
- EPSS 0.35%
- Veröffentlicht 05.10.2026 08:44:56
- Zuletzt bearbeitet 06.10.2026 15:08:38
P4 Search prior to 2026.4.2 does not fail securely when its service authentication token is blank. In affected configurations, an unauthenticated attacker with network access can obtain the highest application privilege, potentially leading to compro...
CVE-2026-103511
- EPSS 0.33%
- Veröffentlicht 05.10.2026 08:40:35
- Zuletzt bearbeitet 06.10.2026 15:08:38
Perforce P4 Search prior to 2026.4.2 does not validate file names supplied to its extension installation feature. An attacker with super-user or service-token privileges can write files with arbitrary content to the P4 Search installation directory.
CVE-2026-100102
- EPSS 0.36%
- Veröffentlicht 05.10.2026 08:27:18
- Zuletzt bearbeitet 06.10.2026 15:08:38
Perforce P4 Search container images prior to 2026.4.2 enable an unauthenticated Java debug interface. An attacker with network access to this interface can execute arbitrary code as the P4 Search service account, potentially leading to compromise of ...
- EPSS 0.42%
- Veröffentlicht 05.10.2026 08:19:47
- Zuletzt bearbeitet 06.10.2026 15:08:38
Perforce P4 Search container images prior to 2026.4.2 reset the service authentication token to a publicly documented default value. An unauthenticated attacker with network access can obtain the highest application privilege, potentially leading to ...
CVE-2026-6902
- EPSS 0.46%
- Veröffentlicht 18.05.2026 07:49:16
- Zuletzt bearbeitet 20.05.2026 07:16:16
A Remote Code Execution vulnerability in P4 (Helix Core) Server's Command-Line Client, prior to the 2025.2 Patch 2, has been fixed to address potential security risks.
CVE-2024-10314
- EPSS 0.49%
- Veröffentlicht 11.11.2024 14:15:14
- Zuletzt bearbeitet 15.04.2026 00:35:42
In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the auto-generation function was identified. Reported by Karol Więsek.
CVE-2024-10344
- EPSS 0.49%
- Veröffentlicht 11.11.2024 14:15:14
- Zuletzt bearbeitet 15.04.2026 00:35:42
In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the refuse function was identified. Reported by Karol Więsek.
CVE-2024-10345
- EPSS 0.49%
- Veröffentlicht 11.11.2024 14:15:14
- Zuletzt bearbeitet 15.04.2026 00:35:42
In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified. Reported by Karol Więsek.
CVE-2024-8067
- EPSS 0.2%
- Veröffentlicht 25.09.2024 01:15:45
- Zuletzt bearbeitet 15.04.2026 00:35:42
In versions of Helix Core prior to 2024.1 Patch 2 (2024.1/2655224) a Windows ANSI API Unicode "best fit" argument injection was identified.
CVE-2023-5759
- EPSS 0.95%
- Veröffentlicht 08.11.2023 16:15:11
- Zuletzt bearbeitet 21.11.2024 08:42:25
In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the buffer was identified. Reported by Jason Geffner.