Vulnerabilities (CVE)

Filtered by vendor 4d Subscribe
Filtered by product Server
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-4770 2 4d, Microsoft 3 4d, Server, Windows 2024-02-28 N/A 7.8 HIGH
An uncontrolled search path element vulnerability has been found on 4D and 4D server Windows executables applications, affecting version 19 R8 100218. This vulnerability consists in a DLL hijacking by replacing x64 shfolder.dll in the installation path, causing an arbitrary code execution.
CVE-2023-30222 1 4d 1 Server 2024-02-28 N/A 7.5 HIGH
An information disclosure vulnerability in 4D SAS 4D Server Application v17, v18, v19 R7 and earlier allows attackers to retrieve password hashes for all users via eavesdropping.
CVE-2023-30223 1 4d 1 Server 2024-02-28 N/A 7.5 HIGH
A broken authentication vulnerability in 4D SAS 4D Server software v17, v18, v19 R7, and earlier allows attackers to send crafted TCP packets containing requests to perform arbitrary actions.