I have been using 4.12 for over a year and I have found three problems.
1) I'm pretty sure the ssh daemon (at least!) is vulnerable, it's a rather old version and I didn't notice any updates to 4.12 other than, well, 5.x
2) All the excellent solutions to various problems put forward in the forums and so on apply to 5.x but not 4.12
3) By default, unless you're running as an NT domain, anyone who types username foo, password bar into a win9x client will get into the ibays unless you explicitly set group permissions -- note that I had assumed that they would be locked out unless an account existed for them on e-smith.
I run 4.12 on a MMX P233 with no speed problems at all, and I run 5.5 on a HP Netserver with a P100 CPU -- again with no problems but it's probably a bit speedier than a strd clone p100, as it was designed as a net server in the first place.
Cheers!