Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Truecrypt Foundation

First CVE: May 4, 2006Active for: 20 yearsTotal CVEs: 8

TrueCrypt Foundation maintains an encryption and disk-protection utility that, despite a narrow product scope, has achieved significant deployment among users prioritizing data confidentiality. The sparse vulnerability record reflects weakness classes centered on information disclosure and cryptographic implementation concerns inherent to full-disk encryption tools. Current severity, exploitation status, and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 79% of tracked vendors
1.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 75% of tracked vendors
5.5
Avg CVSS Score
Higher Avg CVSS Score than 7% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Truecrypt Foundation over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 4, 2006
20 years ago
Most Recent CVE
Mar 19, 2018
3,049 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2015-7358HIGH
The IsDriveLetterAvailable method in Driver/Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, does not properly validate drive letter sym
Oct 3, 20177.830NOYES
CVE-2007-1738MEDIUM
TrueCrypt 4.3, when installed setuid root, allows local users to cause a denial of service (filesystem unavailability) or gain privileges by mounting a crafted TrueCrypt volume, as
Mar 28, 20076.926NOYES
CVE-2015-7359HIGH
The (1) IsVolumeAccessibleByCurrentUser and (2) MountDevice methods in Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, do not check the
Oct 3, 20177.820NONO
CVE-2006-2183HIGH
Untrusted search path vulnerability in Truecrypt 4.1, when running suid root on Linux, allows local users to execute arbitrary commands and gain privileges via a modified PATH envi
May 4, 20067.219NONO
CVE-2014-2885HIGH
Multiple integer overflows in TrueCrypt 7.1a allow local users to (1) obtain sensitive information via vectors involving a crafted item->OriginalLength value in the MainThreadProc
Mar 19, 20187.118NONO
CVE-2014-2884LOW
The ProcessVolumeDeviceControlIrp function in Ntdriver.c in TrueCrypt 7.1a allows local users to bypass access restrictions and obtain sensitive information about arbitrary files v
Mar 19, 20183.316NONO
CVE-2008-3899LOW
TrueCrypt 5.0 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer before and after use, which allows local users to obtain sensitive
Sep 3, 20082.111NONO
CVE-2007-1589LOW
TrueCrypt before 4.3, when set-euid mode is used on Linux, allows local users to cause a denial of service (filesystem unavailability) by dismounting a volume mounted by a differen
Mar 21, 20072.111NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
38%
13%
50%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local4 (50.0%)
Network0 (0.0%)
Unknown4 (50.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (50.0%)
High0 (0.0%)
Unknown4 (50.0%)
User Interaction
None4 (50.0%)
Unknown4 (50.0%)
Required0 (0.0%)
Privileges Required
Low4 (50.0%)
High0 (0.0%)
None0 (0.0%)
Unknown4 (50.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
25.0% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Truecrypt Foundation.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Truecrypt Foundation — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Truecrypt Foundation's Products

View all 2 CNAs →

Top CWEs