4D develops a narrowly scoped line of application server and web server products, including WebStar and its 4D Server platform, with a recurring exposure profile centered on authentication, certificate validation, and XML entity-handling weaknesses. Its vulnerability disclosures frequently acquire public exploit code, reflecting the internet-facing role these server products occupy in web application deployments. Defenders should prioritize patches for this vendor's server components and monitor for public tooling targeting the identified weakness classes; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 4d over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0695HIGH Stack-based buffer overflow in the FTP service for 4D WebSTAR 5.3.2 and earlier allows remote attackers to execute arbitrary code via a long FTP command. | Jul 27, 2004 | 7.5 | 64 | NO | YES |
CVE-2004-0079HIGH The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake t | Nov 23, 2004 | 7.5 | 29 | NO | NO |
CVE-2024-39847HIGH Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read access to files on the applicat | Apr 30, 2026 | 7.5 | 28 | NO | NO |
CVE-2005-1507MEDIUM Buffer overflow in the Tomcat plugin in 4d WebSTAR 5.33 and 5.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long URL. | May 11, 2005 | 5.0 | 24 | NO | YES |
CVE-2004-0112MEDIUM The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, whi | Nov 23, 2004 | 5.0 | 23 | NO | NO |
CVE-2023-30223HIGH A broken authentication vulnerability in 4D SAS 4D Server software v17, v18, v19 R7, and earlier allows attackers to send crafted TCP packets containing requests to perform arbitra | Jun 16, 2023 | 7.5 | 21 | NO | NO |
CVE-2023-30222HIGH An information disclosure vulnerability in 4D SAS 4D Server Application v17, v18, v19 R7 and earlier allows attackers to retrieve password hashes for all users via eavesdropping. | Jun 16, 2023 | 7.5 | 21 | NO | NO |
CVE-2023-4770HIGH An uncontrolled search path element vulnerability has been found on 4D and 4D server Windows executables applications, affecting version 19 R8 100218. This vulnerability consists i | Nov 30, 2023 | 7.8 | 20 | NO | NO |
CVE-2004-0081MEDIUM OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Co | Nov 23, 2004 | 5.0 | 18 | NO | NO |
CVE-2005-3143MEDIUM Unspecified vulnerability in the Mailbox Server for 4D WebStar before 5.3.5 allows attackers to cause a denial of service (crash) via IMAP clients on Mac OS X 10.4 Mail 2. | Oct 5, 2005 | 5.0 | 16 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 4d.
Media articles that mention a CVE ID that affects a product developed by 4d — matched by CVE ID, not by vendor name.