Simsong maintains bulk_extractor, a forensic data-extraction utility focused on recovering artifacts from raw disk and file data, where the observed vulnerabilities cluster around memory-safety issues in parsing and buffer handling. The recurring weakness classes—heap-based buffer overflows and out-of-bounds writes—reflect the memory-unsafe implementation typical of low-level extraction tools that process untrusted and malformed input streams; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Simsong over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-24857CRITICAL `bulk_extractor` is a digital forensics exploitation tool. Starting in version 1.4, `bulk_extractor`’s embedded unrar code has a heap‑buffer‑overflow in the RAR PPM LZ decoding pat | Jan 28, 2026 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Simsong.
Media articles that mention a CVE ID that affects a product developed by Simsong — matched by CVE ID, not by vendor name.