The Sleuth Kit
Sleuthkit · 19 CVEs
Sleuth Kit ISO9660 SUSP Extension Reference Out-of-Bounds Read
Apr 8, 2026
Sleuth Kit APFS Keybag Parser Out-of-Bounds Read
Apr 8, 2026
Sleuth Kit tsk_recover Path Traversal
Apr 8, 2026
OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a cr…
Jan 24, 2023
In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file…
Mar 8, 2020
In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a heap-based buffer over-read in ntfs_dinode_lookup in f…
Mar 8, 2020
An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an out of bounds read on iso9660 while parsing System U…
Aug 2, 2019
An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an off-by-one overwrite due to an underflow on tools/ha…
Aug 2, 2019
The Sleuth Kit 4.6.0 and earlier is affected by: Integer Overflow. The impact is: Opening crafted disk image triggers c…
Jul 18, 2019
In The Sleuth Kit (TSK) through 4.6.4, hfs_cat_traverse in tsk/fs/hfs.c does not properly determine when a key length i…
Nov 29, 2018
An issue was discovered in libtskbase.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds r…
Jun 5, 2018
An issue was discovered in libtskimg.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds re…
Jun 5, 2018
An issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds rea…
Jun 5, 2018
An issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds rea…
Jun 5, 2018
In The Sleuth Kit (TSK) 4.4.2, fls hangs on a corrupt exfat image in tsk_img_read() in tsk/img/img_io.c in libtskimg.a.
Aug 29, 2017
In The Sleuth Kit (TSK) 4.4.2, opening a crafted disk image triggers infinite recursion in dos_load_ext_table() in tsk/…
Aug 29, 2017
In The Sleuth Kit (TSK) 4.4.2, opening a crafted ISO 9660 image triggers an out-of-bounds read in iso9660_proc_dir() in…
Aug 29, 2017
The Sleuth Kit (TSK) 4.0.1 does not properly handle "." (dotfile) file system entries in FAT file systems and other fil…
Sep 29, 2014
Use-after-free vulnerability in ext2fs.c in Brian Carrier The Sleuth Kit (TSK) before 2.09 allows user-assisted remote…
Aug 8, 2007
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-40026 | Sleuth Kit ISO9660 SUSP Extension Reference Out-of-Bounds Read | MEDIUM | 0.18% | Apr 8, 2026 |
| CVE-2026-40025 | Sleuth Kit APFS Keybag Parser Out-of-Bounds Read | MEDIUM | 0.18% | Apr 8, 2026 |
| CVE-2026-40024 | Sleuth Kit tsk_recover Path Traversal | HIGH | 0.21% | Apr 8, 2026 |
| CVE-2022-45639 | OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. NOTE: th… | HIGH | 4.66% | Jan 24, 2023 |
| CVE-2020-10232 | In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file timestamp parsing logic in yaffsfs_istat… | CRITICAL | 2.48% | Mar 8, 2020 |
| CVE-2020-10233 | In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a heap-based buffer over-read in ntfs_dinode_lookup in fs/ntfs.c. | CRITICAL | 2.41% | Mar 8, 2020 |
| CVE-2019-14531 | An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an out of bounds read on iso9660 while parsing System Use Sharing Protocol data in fs/iso9660.c. | CRITICAL | 1.80% | Aug 2, 2019 |
| CVE-2019-14532 | An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an off-by-one overwrite due to an underflow on tools/hashtools/hfind.cpp while using a bogus ha… | CRITICAL | 2.04% | Aug 2, 2019 |
| CVE-2019-1010065 | The Sleuth Kit 4.6.0 and earlier is affected by: Integer Overflow. The impact is: Opening crafted disk image triggers crash in tsk/fs/hfs_dent.c:237. The compo… | MEDIUM | 1.37% | Jul 18, 2019 |
| CVE-2018-19497 | In The Sleuth Kit (TSK) through 4.6.4, hfs_cat_traverse in tsk/fs/hfs.c does not properly determine when a key length is too large, which allows attackers to c… | MEDIUM | 1.52% | Nov 29, 2018 |
| CVE-2018-11740 | An issue was discovered in libtskbase.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the… | HIGH | 1.31% | Jun 5, 2018 |
| CVE-2018-11739 | An issue was discovered in libtskimg.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the f… | HIGH | 1.30% | Jun 5, 2018 |
| CVE-2018-11738 | An issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the fu… | HIGH | 1.33% | Jun 5, 2018 |
| CVE-2018-11737 | An issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the fu… | HIGH | 1.33% | Jun 5, 2018 |
| CVE-2017-13760 | In The Sleuth Kit (TSK) 4.4.2, fls hangs on a corrupt exfat image in tsk_img_read() in tsk/img/img_io.c in libtskimg.a. | MEDIUM | 0.74% | Aug 29, 2017 |
| CVE-2017-13756 | In The Sleuth Kit (TSK) 4.4.2, opening a crafted disk image triggers infinite recursion in dos_load_ext_table() in tsk/vs/dos.c in libtskvs.a, as demonstrated… | MEDIUM | 0.70% | Aug 29, 2017 |
| CVE-2017-13755 | In The Sleuth Kit (TSK) 4.4.2, opening a crafted ISO 9660 image triggers an out-of-bounds read in iso9660_proc_dir() in tsk/fs/iso9660_dent.c in libtskfs.a, as… | MEDIUM | 0.74% | Aug 29, 2017 |
| CVE-2012-5619 | The Sleuth Kit (TSK) 4.0.1 does not properly handle "." (dotfile) file system entries in FAT file systems and other file systems for which . is not a reserved… | LOW | 0.35% | Sep 29, 2014 |
| CVE-2007-4195 | Use-after-free vulnerability in ext2fs.c in Brian Carrier The Sleuth Kit (TSK) before 2.09 allows user-assisted remote attackers to cause a denial of service (… | MEDIUM | 2.13% | Aug 8, 2007 |
Showing 1 to 19 of 19 CVEs