Skip to main content

Vendor/product archive

sleuthkit / the_sleuth_kit CVEs

Beta · best-effort

18 CVEs tagged to sleuthkit / the_sleuth_kit4 Critical, 6 High, 7 Medium, 1 Low, 0 Unrated.

CVE-2026-40026

Published Apr 8, 2026

The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the ISO9660 filesystem parser where the parse_susp() function trusts len_id, len_des, and len_src fie…

CVSS 4.8 · Medium
evidence mentions
5
Buzz score
34.4
Vendor/product tagsBeta · best-effort

CVE-2026-40025

Published Apr 8, 2026

The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the APFS filesystem keybag parser where the wrapped_key_parser class follows attacker-controlled leng…

CVSS 4.8 · Medium
evidence mentions
5
Buzz score
34.4
Vendor/product tagsBeta · best-effort

CVE-2026-40024

Published Apr 8, 2026

The Sleuth Kit through 4.14.0 contains a path traversal vulnerability in tsk_recover that allows an attacker to write files to arbitrary locations outside the intended recovery di…

CVSS 8.4 · High
evidence mentions
4
Buzz score
32.6
Vendor/product tagsBeta · best-effort

CVE-2022-45639

Published Jan 24, 2023

OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. NOTE: third parties have dis…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10233

Published Mar 9, 2020

In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a heap-based buffer over-read in ntfs_dinode_lookup in fs/ntfs.c.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-14531

Published Aug 2, 2019

An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an out of bounds read on iso9660 while parsing System Use Sharing Protocol data in fs/iso9660.c.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-11740

Published Jun 5, 2018

An issue was discovered in libtskbase.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the function tsk_UTF16to…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11739

Published Jun 5, 2018

An issue was discovered in libtskimg.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the function raw_read in…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11738

Published Jun 5, 2018

An issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the function ntfs_make_dat…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11737

Published Jun 5, 2018

An issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the function ntfs_fix_idxr…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2012-5619

Published Sep 29, 2014

The Sleuth Kit (TSK) 4.0.1 does not properly handle "." (dotfile) file system entries in FAT file systems and other file systems for which . is not a reserved name, which allows l…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 1-18 of 18 CVEsPage 1 of 1