sleuthkit CVE Vulnerabilities & Metrics

Focus on sleuthkit vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About sleuthkit Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with sleuthkit. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total sleuthkit CVEs: 15
Earliest CVE date: 29 Sep 2014, 22:55 UTC
Latest CVE date: 24 Jan 2023, 02:15 UTC

Latest CVE reference: CVE-2022-45639

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical sleuthkit CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.2

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 2
4.0-6.9 10
7.0-8.9 4
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS sleuthkit CVEs

These are the five CVEs with the highest CVSS scores for sleuthkit, sorted by severity first and recency.

All CVEs for sleuthkit

CVE-2022-45639 sleuthkit vulnerability CVSS: 0 24 Jan 2023, 02:15 UTC

OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. NOTE: third parties have disputed this because there is no analysis showing that the backtick command executes outside the context of the user account that entered the command line.

CVE-2020-10233 sleuthkit vulnerability CVSS: 6.4 09 Mar 2020, 00:15 UTC

In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a heap-based buffer over-read in ntfs_dinode_lookup in fs/ntfs.c.

CVE-2020-10232 sleuthkit vulnerability CVSS: 7.5 09 Mar 2020, 00:15 UTC

In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file timestamp parsing logic in yaffsfs_istat() in fs/yaffs.c.

CVE-2019-14532 sleuthkit vulnerability CVSS: 7.5 02 Aug 2019, 15:15 UTC

An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an off-by-one overwrite due to an underflow on tools/hashtools/hfind.cpp while using a bogus hash table.

CVE-2019-14531 sleuthkit vulnerability CVSS: 7.5 02 Aug 2019, 15:15 UTC

An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an out of bounds read on iso9660 while parsing System Use Sharing Protocol data in fs/iso9660.c.

CVE-2019-1010065 sleuthkit vulnerability CVSS: 4.3 18 Jul 2019, 17:15 UTC

The Sleuth Kit 4.6.0 and earlier is affected by: Integer Overflow. The impact is: Opening crafted disk image triggers crash in tsk/fs/hfs_dent.c:237. The component is: Overflow in fls tool used on HFS image. Bug is in tsk/fs/hfs.c file in function hfs_cat_traverse() in lines: 952, 1062. The attack vector is: Victim must open a crafted HFS filesystem image.

CVE-2018-1000838 sleuthkit vulnerability CVSS: 7.5 20 Dec 2018, 15:29 UTC

autopsy version <= 4.9.0 contains a XML External Entity (XXE) vulnerability in CaseMetadata XML Parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Specially crafted CaseMetadata.

CVE-2018-19497 sleuthkit vulnerability CVSS: 4.3 29 Nov 2018, 23:29 UTC

In The Sleuth Kit (TSK) through 4.6.4, hfs_cat_traverse in tsk/fs/hfs.c does not properly determine when a key length is too large, which allows attackers to cause a denial of service (SEGV on unknown address with READ memory access in a tsk_getu16 call in hfs_dir_open_meta_cb in tsk/fs/hfs_dent.c).

CVE-2018-11740 sleuthkit vulnerability CVSS: 5.8 05 Jun 2018, 11:29 UTC

An issue was discovered in libtskbase.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the function tsk_UTF16toUTF8 in tsk/base/tsk_unicode.c which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service attack.

CVE-2018-11739 sleuthkit vulnerability CVSS: 5.8 05 Jun 2018, 11:29 UTC

An issue was discovered in libtskimg.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the function raw_read in tsk/img/raw.c which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service attack.

CVE-2018-11738 sleuthkit vulnerability CVSS: 5.8 05 Jun 2018, 11:29 UTC

An issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the function ntfs_make_data_run in tsk/fs/ntfs.c which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service attack.

CVE-2018-11737 sleuthkit vulnerability CVSS: 5.8 05 Jun 2018, 11:29 UTC

An issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the function ntfs_fix_idxrec in tsk/fs/ntfs_dent.cpp which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service.

CVE-2017-13760 sleuthkit vulnerability CVSS: 4.3 29 Aug 2017, 23:29 UTC

In The Sleuth Kit (TSK) 4.4.2, fls hangs on a corrupt exfat image in tsk_img_read() in tsk/img/img_io.c in libtskimg.a.

CVE-2017-13756 sleuthkit vulnerability CVSS: 4.3 29 Aug 2017, 22:29 UTC

In The Sleuth Kit (TSK) 4.4.2, opening a crafted disk image triggers infinite recursion in dos_load_ext_table() in tsk/vs/dos.c in libtskvs.a, as demonstrated by mmls.

CVE-2017-13755 sleuthkit vulnerability CVSS: 4.3 29 Aug 2017, 22:29 UTC

In The Sleuth Kit (TSK) 4.4.2, opening a crafted ISO 9660 image triggers an out-of-bounds read in iso9660_proc_dir() in tsk/fs/iso9660_dent.c in libtskfs.a, as demonstrated by fls.

CVE-2012-5619 sleuthkit vulnerability CVSS: 2.1 29 Sep 2014, 22:55 UTC

The Sleuth Kit (TSK) 4.0.1 does not properly handle "." (dotfile) file system entries in FAT file systems and other file systems for which . is not a reserved name, which allows local users to hide activities it more difficult to conduct forensics activities, as demonstrated by Flame.