Guidance Software's vulnerability profile concentrates in its EnCase digital forensics and e-discovery platform, a specialized investigation tool with a narrower deployment footprint than consumer or broad infrastructure products. The durable signal centers on memory-handling issues and bounds-checking weaknesses characteristic of native forensic analysis code. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Guidance Software over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-4201MEDIUM Guidance Software EnCase 6.2 and 6.5 does not properly handle a volume with more than 25 partitions, which might allow remote attackers to prevent examination of certain data, a re | Aug 8, 2007 | 5.0 | 15 | NO | NO |
CVE-2007-4035MEDIUM Guidance Software EnCase does not properly handle (1) certain malformed MBR partition tables with many entries, which allows remote attackers to prevent logical collection of a dis | Jul 27, 2007 | 5.0 | 15 | NO | NO |
CVE-2007-4194MEDIUM Guidance Software EnCase 5.0 allows user-assisted remote attackers to cause a denial of service (stack memory consumption) and possibly have other unspecified impact via a malforme | Aug 8, 2007 | 4.3 | 14 | NO | NO |
CVE-2007-4202MEDIUM Guidance Software EnCase Enterprise Edition (EEE) 6 does not properly verify the identity of the acquisition target during communication with the EnCase Servlet (EEE servlet), whic | Aug 8, 2007 | 4.3 | 14 | NO | NO |
CVE-2007-4036MEDIUM Guidance Software EnCase allows user-assisted remote attackers to cause a denial of service via (1) a corrupted Microsoft Exchange database, which triggers an application crash whe | Jul 27, 2007 | 4.3 | 14 | NO | NO |
CVE-2007-4037MEDIUM Guidance Software EnCase allows user-assisted attackers to trigger a buffer over-read and application crash via a malformed NTFS filesystem containing a modified FILE record with a | Jul 27, 2007 | 4.3 | 14 | NO | NO |
EnCase Forensic Edition 4.18a does not support Device Configuration Overlays (DCO), which allows attackers to hide information without detection. | May 13, 2005 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Guidance Software.
Media articles that mention a CVE ID that affects a product developed by Guidance Software — matched by CVE ID, not by vendor name.