Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

4d

First CVE: Mar 31, 2000Active for: 26 yearsTotal CVEs: 14
36.8
VTI Score
Medium

4D develops a narrowly scoped line of application server and web server products, including WebStar and its 4D Server platform, with a recurring exposure profile centered on authentication, certificate validation, and XML entity-handling weaknesses. Its vulnerability disclosures frequently acquire public exploit code, reflecting the internet-facing role these server products occupy in web application deployments. Defenders should prioritize patches for this vendor's server components and monitor for public tooling targeting the identified weakness classes; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 29% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by 4d over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 31, 2000
26 years ago
Most Recent CVE
Apr 30, 2026
85 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2004-0695HIGH
Stack-based buffer overflow in the FTP service for 4D WebSTAR 5.3.2 and earlier allows remote attackers to execute arbitrary code via a long FTP command.
Jul 27, 20047.564NOYES
CVE-2004-0079HIGH
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake t
Nov 23, 20047.529NONO
CVE-2024-39847HIGH
Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read access to files on the applicat
Apr 30, 20267.528NONO
CVE-2005-1507MEDIUM
Buffer overflow in the Tomcat plugin in 4d WebSTAR 5.33 and 5.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long URL.
May 11, 20055.024NOYES
CVE-2004-0112MEDIUM
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, whi
Nov 23, 20045.023NONO
CVE-2023-30223HIGH
A broken authentication vulnerability in 4D SAS 4D Server software v17, v18, v19 R7, and earlier allows attackers to send crafted TCP packets containing requests to perform arbitra
Jun 16, 20237.521NONO
CVE-2023-30222HIGH
An information disclosure vulnerability in 4D SAS 4D Server Application v17, v18, v19 R7 and earlier allows attackers to retrieve password hashes for all users via eavesdropping.
Jun 16, 20237.521NONO
CVE-2023-4770HIGH
An uncontrolled search path element vulnerability has been found on 4D and 4D server Windows executables applications, affecting version 19 R8 100218. This vulnerability consists i
Nov 30, 20237.820NONO
CVE-2004-0081MEDIUM
OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Co
Nov 23, 20045.018NONO
CVE-2005-3143MEDIUM
Unspecified vulnerability in the Mailbox Server for 4D WebStar before 5.3.5 allows attackers to cause a denial of service (crash) via IMAP clients on Mac OS X 10.4 Mail 2.
Oct 5, 20055.016NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
50%
43%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local1 (7.1%)
Network4 (28.6%)
Unknown9 (64.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (35.7%)
High0 (0.0%)
Unknown9 (64.3%)
User Interaction
None4 (28.6%)
Unknown9 (64.3%)
Required1 (7.1%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None5 (35.7%)
Unknown9 (64.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
7.1% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
14.3% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by 4d.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by 4d — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For 4d's Products

View all 3 CNAs →

Top CWEs