4D records
14 published records for vendor 4d.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 7.1%
- Pre-auth RCE
- 2
- With a fix record
- 21.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-125 Out-of-bounds Read1
- CWE-287 Improper Authentication1
- CWE-295 Improper Certificate Validation1
- CWE-427 Uncontrolled Search Path Element1
- CWE-476 NULL Pointer Dereference1
- CWE-611 Improper Restriction of XML External Entity Reference1
The weakness classes this vendor ships most often: where to look.
CWEAll records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2004-0695Weaponized | Stack-based buffer overflow in the FTP service for 4D WebSTAR 5.3.2 and earlier allows remote attackers to execute arbitrary code via a long4d · webstar | High7.5 | — | 38.2% | Jul 27, 2004 |
34Monitor | CVE-2024-39847No exploit | Arbitrary File Read and Server Side Request Forgery via XML External Entities in 4D Server SOAP4d · server · CWE-611 | High8.7 | — | 0.4% | Apr 30, 2026 |
33Monitor | CVE-2004-0079No exploit | The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (openssl · openssl · CWE-476 | High7.5 | — | 9.5% | Nov 23, 2004 |
31Monitor | CVE-2023-4770No exploit | Uncontrolled Search Path Element Vulnerability in 4D and 4D Windows Server4d · 4d · CWE-427 | High7.8 | — | 0.3% | Nov 30, 2023 |
30Monitor | CVE-2023-30222No exploit | An information disclosure vulnerability in 4D SAS 4D Server Application v17, v18, v19 R7 and earlier allows attackers to retrieve password h4d · server · CWE-295 | High7.5 | — | 1.2% | Jun 16, 2023 |
30Monitor | CVE-2023-30223No exploit | A broken authentication vulnerability in 4D SAS 4D Server software v17, v18, v19 R7, and earlier allows attackers to send crafted TCP packet4d · server · CWE-287 | High7.5 | — | 1.1% | Jun 16, 2023 |
23Monitor | CVE-2004-0112No exploit | The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of openssl · openssl · CWE-125 | Medium5.0 | — | 10.4% | Nov 23, 2004 |
22Monitor | CVE-2004-0081No exploit | OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infiopenssl · openssl | Medium5.0 | — | 7.2% | Nov 23, 2004 |
22Monitor | CVE-2005-1507Proof of concept | Buffer overflow in the Tomcat plugin in 4d WebSTAR 5.33 and 5.4 allows remote attackers to cause a denial of service and possibly execute ar4d · webstar | Medium5.0 | — | 5.7% | May 11, 2005 |
21Monitor | CVE-2000-0290No exploit | Buffer overflow in Webstar HTTP server allows remote attackers to cause a denial of service via a long GET request.4d · webstar http server | Medium5.0 | — | 1.9% | Mar 31, 2000 |
20Monitor | CVE-2004-0696No exploit | The ShellExample.cgi script in 4D WebSTAR 5.3.2 and earlier allows remote attackers to list arbitrary directories via a URL with the desired4d · webstar | Medium5.0 | — | 1.4% | Jul 27, 2004 |
20Monitor | CVE-2004-0697No exploit | Unknown vulnerability in 4D WebSTAR 5.3.2 and earlier allows remote attackers to read the php.ini configuration file and possibly obtain sen4d · webstar | Medium5.0 | — | 1.4% | Jul 27, 2004 |
20Monitor | CVE-2005-3143No exploit | Unspecified vulnerability in the Mailbox Server for 4D WebStar before 5.3.5 allows attackers to cause a denial of service (crash) via IMAP c4d · webstar | Medium5.0 | — | 1.3% | Oct 5, 2005 |
14Monitor | CVE-2004-0698No exploit | 4D WebSTAR 5.3.2 and earlier allows local users to read and modify arbitrary files via a symlink attack.4d · webstar | Low3.6 | — | 0.3% | Jul 27, 2004 |
- CVE-2004-069541Plan
Stack-based buffer overflow in the FTP service for 4D WebSTAR 5.3.2 and earlier allows remote attackers to execute arbitrary code via a long
HighCVSS 7.5WeaponizedEPSS 38%4d · webstarJul 27, 2004
- CVE-2024-3984734Monitor
Arbitrary File Read and Server Side Request Forgery via XML External Entities in 4D Server SOAP
HighCVSS 8.7No exploitEPSS 0%4d · serverApr 30, 2026
- CVE-2004-007933Monitor
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (
HighCVSS 7.5No exploitEPSS 10%openssl · opensslNov 23, 2004
- CVE-2023-477031Monitor
Uncontrolled Search Path Element Vulnerability in 4D and 4D Windows Server
HighCVSS 7.8No exploitEPSS 0%4d · 4dNov 30, 2023
- CVE-2023-3022230Monitor
An information disclosure vulnerability in 4D SAS 4D Server Application v17, v18, v19 R7 and earlier allows attackers to retrieve password h
HighCVSS 7.5No exploitEPSS 1%4d · serverJun 16, 2023
- CVE-2023-3022330Monitor
A broken authentication vulnerability in 4D SAS 4D Server software v17, v18, v19 R7, and earlier allows attackers to send crafted TCP packet
HighCVSS 7.5No exploitEPSS 1%4d · serverJun 16, 2023
- CVE-2004-011223Monitor
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of
MediumCVSS 5.0No exploitEPSS 10%openssl · opensslNov 23, 2004
- CVE-2004-008122Monitor
OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infi
MediumCVSS 5.0No exploitEPSS 7%openssl · opensslNov 23, 2004
- CVE-2005-150722Monitor
Buffer overflow in the Tomcat plugin in 4d WebSTAR 5.33 and 5.4 allows remote attackers to cause a denial of service and possibly execute ar
MediumCVSS 5.0Proof of conceptEPSS 6%4d · webstarMay 11, 2005
- CVE-2000-029021Monitor
Buffer overflow in Webstar HTTP server allows remote attackers to cause a denial of service via a long GET request.
MediumCVSS 5.0No exploitEPSS 2%4d · webstar http serverMar 31, 2000
- CVE-2004-069620Monitor
The ShellExample.cgi script in 4D WebSTAR 5.3.2 and earlier allows remote attackers to list arbitrary directories via a URL with the desired
MediumCVSS 5.0No exploitEPSS 1%4d · webstarJul 27, 2004
- CVE-2004-069720Monitor
Unknown vulnerability in 4D WebSTAR 5.3.2 and earlier allows remote attackers to read the php.ini configuration file and possibly obtain sen
MediumCVSS 5.0No exploitEPSS 1%4d · webstarJul 27, 2004
- CVE-2005-314320Monitor
Unspecified vulnerability in the Mailbox Server for 4D WebStar before 5.3.5 allows attackers to cause a denial of service (crash) via IMAP c
MediumCVSS 5.0No exploitEPSS 1%4d · webstarOct 5, 2005
- CVE-2004-069814Monitor
4D WebSTAR 5.3.2 and earlier allows local users to read and modify arbitrary files via a symlink attack.
LowCVSS 3.6No exploitEPSS 0%4d · webstarJul 27, 2004