Brian Carrier maintains The Sleuth Kit, a widely used digital forensics and incident-response toolkit that serves security analysts and law-enforcement investigators globally. The toolkit's vulnerability profile reflects the complexity inherent to forensic parsers and file-system analysis tools that must handle untrusted or malformed evidence artifacts. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Brian Carrier over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-4196MEDIUM icat in Brian Carrier The Sleuth Kit (TSK) before 2.09 misinterprets a certain memory location as the holder of a loop iteration count, which allows user-assisted remote attackers | Aug 8, 2007 | 4.3 | 14 | NO | NO |
CVE-2007-4197MEDIUM icat in Brian Carrier The Sleuth Kit (TSK) before 2.09 omits NULL pointer checks in certain code paths, which allows user-assisted remote attackers to cause a denial of service (NU | Aug 8, 2007 | 4.3 | 14 | NO | NO |
CVE-2007-4198MEDIUM The fs_data_put_str function in ntfs.c in fls in Brian Carrier The Sleuth Kit (TSK) before 2.09 does not validate a certain length value, which allows user-assisted remote attacker | Aug 8, 2007 | 4.3 | 14 | NO | NO |
CVE-2007-4199MEDIUM Brian Carrier The Sleuth Kit (TSK) before 2.09 allows user-assisted remote attackers to cause a denial of service (application crash) and prevent examination of certain NTFS files | Aug 8, 2007 | 4.3 | 14 | NO | NO |
CVE-2007-4200MEDIUM ntfs.c in fsstat in Brian Carrier The Sleuth Kit (TSK) before 2.09 interprets a certain variable as a byte count rather than a count of 32-bit integers, which allows user-assisted | Aug 8, 2007 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Brian Carrier.
Media articles that mention a CVE ID that affects a product developed by Brian Carrier — matched by CVE ID, not by vendor name.