Vulnerabilities > Sleuthkit > High

DATE CVE VULNERABILITY TITLE RISK
2023-01-24 CVE-2022-45639 OS Command Injection vulnerability in Sleuthkit the Sleuth KIT 4.11.1
OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter.
local
low complexity
sleuthkit CWE-78
7.8
2019-08-02 CVE-2019-14531 Out-of-bounds Read vulnerability in Sleuthkit the Sleuth KIT 4.6.6
An issue was discovered in The Sleuth Kit (TSK) 4.6.6.
network
low complexity
sleuthkit CWE-125
7.5
2018-12-20 CVE-2018-1000838 XXE vulnerability in Sleuthkit Autopsy
autopsy version <= 4.9.0 contains a XML External Entity (XXE) vulnerability in CaseMetadata XML Parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.
network
low complexity
sleuthkit CWE-611
7.5