sleuthkit records
19 published records for vendor sleuthkit.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 42.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-125 Out-of-bounds Read10
- CWE-190 Integer Overflow or Wraparound1
- CWE-193 Off-by-one Error1
- CWE-20 Improper Input Validation1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-611 Improper Restriction of XML External Entity Reference1
The weakness classes this vendor ships most often: where to look.
CWEAll records
19 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2018-1000838No exploit | autopsy version <= 4.9.0 contains a XML External Entity (XXE) vulnerability in CaseMetadata XML Parser that can result in Disclosure of confsleuthkit · autopsy · CWE-611 | Critical10.0 | — | 2.5% | Dec 20, 2018 |
40Plan | CVE-2020-10232No exploit | In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file timestamp parsing logsleuthkit · the sleuth kit · CWE-787 | Critical9.8 | — | 2.5% | Mar 8, 2020 |
40Plan | CVE-2019-14532No exploit | An issue was discovered in The Sleuth Kit (TSK) 4.6.6.sleuthkit · the sleuth kit · CWE-193 | Critical9.8 | — | 2.1% | Aug 2, 2019 |
40Plan | CVE-2019-14531No exploit | An issue was discovered in The Sleuth Kit (TSK) 4.6.6.sleuthkit · the sleuth kit · CWE-125 | Critical9.8 | — | 1.8% | Aug 2, 2019 |
37Monitor | CVE-2020-10233No exploit | In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a heap-based buffer over-read in ntfs_dinode_lookup in fs/ntfs.c.sleuthkit · the sleuth kit · CWE-125 | Critical9.1 | — | 2.4% | Mar 8, 2020 |
33Monitor | CVE-2026-40024No exploit | Sleuth Kit tsk_recover Path Traversalsleuthkit · the sleuth kit · CWE-22 | High8.4 | — | 0.2% | Apr 8, 2026 |
32Monitor | CVE-2022-45639Proof of concept | OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m sleuthkit · the sleuth kit · CWE-78 | High7.8 | — | 4.7% | Jan 23, 2023 |
32Monitor | CVE-2018-11738No exploit | An issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1.sleuthkit · the sleuth kit · CWE-125 | High8.1 | — | 1.3% | Jun 5, 2018 |
32Monitor | CVE-2018-11737No exploit | An issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1.sleuthkit · the sleuth kit · CWE-125 | High8.1 | — | 1.3% | Jun 5, 2018 |
32Monitor | CVE-2018-11740No exploit | An issue was discovered in libtskbase.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1.sleuthkit · the sleuth kit · CWE-125 | High8.1 | — | 1.3% | Jun 5, 2018 |
32Monitor | CVE-2018-11739No exploit | An issue was discovered in libtskimg.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1.sleuthkit · the sleuth kit · CWE-125 | High8.1 | — | 1.3% | Jun 5, 2018 |
26Monitor | CVE-2018-19497No exploit | In The Sleuth Kit (TSK) through 4.6.4, hfs_cat_traverse in tsk/fs/hfs.c does not properly determine when a key length is too large, which alsleuthkit · the sleuth kit · CWE-125 | Medium6.5 | — | 1.5% | Nov 29, 2018 |
26Monitor | CVE-2019-1010065No exploit | The Sleuth Kit 4.6.0 and earlier is affected by: Integer Overflow.sleuthkit · the sleuth kit · CWE-190 | Medium6.5 | — | 1.4% | Jul 18, 2019 |
22Monitor | CVE-2017-13755No exploit | In The Sleuth Kit (TSK) 4.4.2, opening a crafted ISO 9660 image triggers an out-of-bounds read in iso9660_proc_dir() in tsk/fs/iso9660_dent.sleuthkit · the sleuth kit · CWE-125 | Medium5.5 | — | 0.7% | Aug 29, 2017 |
22Monitor | CVE-2017-13760No exploit | In The Sleuth Kit (TSK) 4.4.2, fls hangs on a corrupt exfat image in tsk_img_read() in tsk/img/img_io.c in libtskimg.a.sleuthkit · the sleuth kit · CWE-119 | Medium5.5 | — | 0.7% | Aug 29, 2017 |
22Monitor | CVE-2017-13756No exploit | In The Sleuth Kit (TSK) 4.4.2, opening a crafted disk image triggers infinite recursion in dos_load_ext_table() in tsk/vs/dos.c in libtskvs.sleuthkit · the sleuth kit · CWE-835 | Medium5.5 | — | 0.7% | Aug 29, 2017 |
19Monitor | CVE-2026-40026No exploit | Sleuth Kit ISO9660 SUSP Extension Reference Out-of-Bounds Readsleuthkit · the sleuth kit · CWE-125 | Medium4.8 | — | 0.2% | Apr 8, 2026 |
19Monitor | CVE-2026-40025No exploit | Sleuth Kit APFS Keybag Parser Out-of-Bounds Readsleuthkit · the sleuth kit · CWE-125 | Medium4.8 | — | 0.2% | Apr 8, 2026 |
8Monitor | CVE-2012-5619No exploit | The Sleuth Kit (TSK) 4.0.1 does not properly handle "." (dotfile) file system entries in FAT file systems and other file systems for which .sleuthkit · the sleuth kit · CWE-20 | Low2.1 | — | 0.4% | Sep 29, 2014 |
- CVE-2018-100083841Plan
autopsy version <= 4.9.0 contains a XML External Entity (XXE) vulnerability in CaseMetadata XML Parser that can result in Disclosure of conf
CriticalCVSS 10.0No exploitEPSS 3%sleuthkit · autopsyDec 20, 2018
- CVE-2020-1023240Plan
In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file timestamp parsing log
CriticalCVSS 9.8No exploitEPSS 2%sleuthkit · the sleuth kitMar 8, 2020
- CVE-2019-1453240Plan
An issue was discovered in The Sleuth Kit (TSK) 4.6.6.
CriticalCVSS 9.8No exploitEPSS 2%sleuthkit · the sleuth kitAug 2, 2019
- CVE-2019-1453140Plan
An issue was discovered in The Sleuth Kit (TSK) 4.6.6.
CriticalCVSS 9.8No exploitEPSS 2%sleuthkit · the sleuth kitAug 2, 2019
- CVE-2020-1023337Monitor
In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a heap-based buffer over-read in ntfs_dinode_lookup in fs/ntfs.c.
CriticalCVSS 9.1No exploitEPSS 2%sleuthkit · the sleuth kitMar 8, 2020
- CVE-2026-4002433Monitor
Sleuth Kit tsk_recover Path Traversal
HighCVSS 8.4No exploitEPSS 0%sleuthkit · the sleuth kitApr 8, 2026
- CVE-2022-4563932Monitor
OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m
HighCVSS 7.8Proof of conceptEPSS 5%sleuthkit · the sleuth kitJan 23, 2023
- CVE-2018-1173832Monitor
An issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1.
HighCVSS 8.1No exploitEPSS 1%sleuthkit · the sleuth kitJun 5, 2018
- CVE-2018-1173732Monitor
An issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1.
HighCVSS 8.1No exploitEPSS 1%sleuthkit · the sleuth kitJun 5, 2018
- CVE-2018-1174032Monitor
An issue was discovered in libtskbase.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1.
HighCVSS 8.1No exploitEPSS 1%sleuthkit · the sleuth kitJun 5, 2018
- CVE-2018-1173932Monitor
An issue was discovered in libtskimg.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1.
HighCVSS 8.1No exploitEPSS 1%sleuthkit · the sleuth kitJun 5, 2018
- CVE-2018-1949726Monitor
In The Sleuth Kit (TSK) through 4.6.4, hfs_cat_traverse in tsk/fs/hfs.c does not properly determine when a key length is too large, which al
MediumCVSS 6.5No exploitEPSS 2%sleuthkit · the sleuth kitNov 29, 2018
- CVE-2019-101006526Monitor
The Sleuth Kit 4.6.0 and earlier is affected by: Integer Overflow.
MediumCVSS 6.5No exploitEPSS 1%sleuthkit · the sleuth kitJul 18, 2019
- CVE-2017-1375522Monitor
In The Sleuth Kit (TSK) 4.4.2, opening a crafted ISO 9660 image triggers an out-of-bounds read in iso9660_proc_dir() in tsk/fs/iso9660_dent.
MediumCVSS 5.5No exploitEPSS 1%sleuthkit · the sleuth kitAug 29, 2017
- CVE-2017-1376022Monitor
In The Sleuth Kit (TSK) 4.4.2, fls hangs on a corrupt exfat image in tsk_img_read() in tsk/img/img_io.c in libtskimg.a.
MediumCVSS 5.5No exploitEPSS 1%sleuthkit · the sleuth kitAug 29, 2017
- CVE-2017-1375622Monitor
In The Sleuth Kit (TSK) 4.4.2, opening a crafted disk image triggers infinite recursion in dos_load_ext_table() in tsk/vs/dos.c in libtskvs.
MediumCVSS 5.5No exploitEPSS 1%sleuthkit · the sleuth kitAug 29, 2017
- CVE-2026-4002619Monitor
Sleuth Kit ISO9660 SUSP Extension Reference Out-of-Bounds Read
MediumCVSS 4.8No exploitEPSS 0%sleuthkit · the sleuth kitApr 8, 2026
- CVE-2026-4002519Monitor
Sleuth Kit APFS Keybag Parser Out-of-Bounds Read
MediumCVSS 4.8No exploitEPSS 0%sleuthkit · the sleuth kitApr 8, 2026
- CVE-2012-56198Monitor
The Sleuth Kit (TSK) 4.0.1 does not properly handle "." (dotfile) file system entries in FAT file systems and other file systems for which .
LowCVSS 2.1No exploitEPSS 0%sleuthkit · the sleuth kitSep 29, 2014