Записи 4D
14 опубликованных записей вендора 4d.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 7,1 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 21,4 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-125 Out-of-bounds Read1
- CWE-287 Improper Authentication1
- CWE-295 Improper Certificate Validation1
- CWE-427 Uncontrolled Search Path Element1
- CWE-476 NULL Pointer Dereference1
- CWE-611 Improper Restriction of XML External Entity Reference1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
14 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2004-0695Готовый эксплойт | Stack-based buffer overflow in the FTP service for 4D WebSTAR 5.3.2 and earlier allows remote attackers to execute arbitrary code via a long4d · webstar | Высокая7,5 | — | 38,2 % | 27 июл. 2004 г. |
34Наблюдать | CVE-2024-39847Эксплойта нет | Arbitrary File Read and Server Side Request Forgery via XML External Entities in 4D Server SOAP4d · server · CWE-611 | Высокая8,7 | — | 0,4 % | 30 апр. 2026 г. |
33Наблюдать | CVE-2004-0079Эксплойта нет | The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (openssl · openssl · CWE-476 | Высокая7,5 | — | 9,5 % | 23 нояб. 2004 г. |
31Наблюдать | CVE-2023-4770Эксплойта нет | Uncontrolled Search Path Element Vulnerability in 4D and 4D Windows Server4d · 4d · CWE-427 | Высокая7,8 | — | 0,3 % | 30 нояб. 2023 г. |
30Наблюдать | CVE-2023-30222Эксплойта нет | An information disclosure vulnerability in 4D SAS 4D Server Application v17, v18, v19 R7 and earlier allows attackers to retrieve password h4d · server · CWE-295 | Высокая7,5 | — | 1,2 % | 16 июн. 2023 г. |
30Наблюдать | CVE-2023-30223Эксплойта нет | A broken authentication vulnerability in 4D SAS 4D Server software v17, v18, v19 R7, and earlier allows attackers to send crafted TCP packet4d · server · CWE-287 | Высокая7,5 | — | 1,1 % | 16 июн. 2023 г. |
23Наблюдать | CVE-2004-0112Эксплойта нет | The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of openssl · openssl · CWE-125 | Средняя5,0 | — | 10,4 % | 23 нояб. 2004 г. |
22Наблюдать | CVE-2004-0081Эксплойта нет | OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infiopenssl · openssl | Средняя5,0 | — | 7,2 % | 23 нояб. 2004 г. |
22Наблюдать | CVE-2005-1507Proof of concept | Buffer overflow in the Tomcat plugin in 4d WebSTAR 5.33 and 5.4 allows remote attackers to cause a denial of service and possibly execute ar4d · webstar | Средняя5,0 | — | 5,7 % | 11 мая 2005 г. |
21Наблюдать | CVE-2000-0290Эксплойта нет | Buffer overflow in Webstar HTTP server allows remote attackers to cause a denial of service via a long GET request.4d · webstar http server | Средняя5,0 | — | 1,9 % | 31 мар. 2000 г. |
20Наблюдать | CVE-2004-0696Эксплойта нет | The ShellExample.cgi script in 4D WebSTAR 5.3.2 and earlier allows remote attackers to list arbitrary directories via a URL with the desired4d · webstar | Средняя5,0 | — | 1,4 % | 27 июл. 2004 г. |
20Наблюдать | CVE-2004-0697Эксплойта нет | Unknown vulnerability in 4D WebSTAR 5.3.2 and earlier allows remote attackers to read the php.ini configuration file and possibly obtain sen4d · webstar | Средняя5,0 | — | 1,4 % | 27 июл. 2004 г. |
20Наблюдать | CVE-2005-3143Эксплойта нет | Unspecified vulnerability in the Mailbox Server for 4D WebStar before 5.3.5 allows attackers to cause a denial of service (crash) via IMAP c4d · webstar | Средняя5,0 | — | 1,3 % | 5 окт. 2005 г. |
14Наблюдать | CVE-2004-0698Эксплойта нет | 4D WebSTAR 5.3.2 and earlier allows local users to read and modify arbitrary files via a symlink attack.4d · webstar | Низкая3,6 | — | 0,3 % | 27 июл. 2004 г. |
- CVE-2004-069541В плане
Stack-based buffer overflow in the FTP service for 4D WebSTAR 5.3.2 and earlier allows remote attackers to execute arbitrary code via a long
ВысокаяCVSS 7,5Готовый эксплойтEPSS 38 %4d · webstar27 июл. 2004 г.
- CVE-2024-3984734Наблюдать
Arbitrary File Read and Server Side Request Forgery via XML External Entities in 4D Server SOAP
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %4d · server30 апр. 2026 г.
- CVE-2004-007933Наблюдать
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (
ВысокаяCVSS 7,5Эксплойта нетEPSS 10 %openssl · openssl23 нояб. 2004 г.
- CVE-2023-477031Наблюдать
Uncontrolled Search Path Element Vulnerability in 4D and 4D Windows Server
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %4d · 4d30 нояб. 2023 г.
- CVE-2023-3022230Наблюдать
An information disclosure vulnerability in 4D SAS 4D Server Application v17, v18, v19 R7 and earlier allows attackers to retrieve password h
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %4d · server16 июн. 2023 г.
- CVE-2023-3022330Наблюдать
A broken authentication vulnerability in 4D SAS 4D Server software v17, v18, v19 R7, and earlier allows attackers to send crafted TCP packet
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %4d · server16 июн. 2023 г.
- CVE-2004-011223Наблюдать
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of
СредняяCVSS 5,0Эксплойта нетEPSS 10 %openssl · openssl23 нояб. 2004 г.
- CVE-2004-008122Наблюдать
OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infi
СредняяCVSS 5,0Эксплойта нетEPSS 7 %openssl · openssl23 нояб. 2004 г.
- CVE-2005-150722Наблюдать
Buffer overflow in the Tomcat plugin in 4d WebSTAR 5.33 and 5.4 allows remote attackers to cause a denial of service and possibly execute ar
СредняяCVSS 5,0Proof of conceptEPSS 6 %4d · webstar11 мая 2005 г.
- CVE-2000-029021Наблюдать
Buffer overflow in Webstar HTTP server allows remote attackers to cause a denial of service via a long GET request.
СредняяCVSS 5,0Эксплойта нетEPSS 2 %4d · webstar http server31 мар. 2000 г.
- CVE-2004-069620Наблюдать
The ShellExample.cgi script in 4D WebSTAR 5.3.2 and earlier allows remote attackers to list arbitrary directories via a URL with the desired
СредняяCVSS 5,0Эксплойта нетEPSS 1 %4d · webstar27 июл. 2004 г.
- CVE-2004-069720Наблюдать
Unknown vulnerability in 4D WebSTAR 5.3.2 and earlier allows remote attackers to read the php.ini configuration file and possibly obtain sen
СредняяCVSS 5,0Эксплойта нетEPSS 1 %4d · webstar27 июл. 2004 г.
- CVE-2005-314320Наблюдать
Unspecified vulnerability in the Mailbox Server for 4D WebStar before 5.3.5 allows attackers to cause a denial of service (crash) via IMAP c
СредняяCVSS 5,0Эксплойта нетEPSS 1 %4d · webstar5 окт. 2005 г.
- CVE-2004-069814Наблюдать
4D WebSTAR 5.3.2 and earlier allows local users to read and modify arbitrary files via a symlink attack.
НизкаяCVSS 3,6Эксплойта нетEPSS 0 %4d · webstar27 июл. 2004 г.