Debian GNU/Linux
First CVE: Feb 9, 2005Active for: 21 years
645
CVEs Published
More CVEs Published than 88% of tracked CNAs
40.3
Avg CVEs / Year
More Avg CVEs / Year than 81% of tracked CNAs
6.6
Avg CVSS Score
Higher Avg CVSS Score than 28% of tracked CNAs
0.5%
In CISA KEV
Higher KEV Rate than 85% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by Debian GNU/Linux as a CNA, 30.7% affect products that Debian GNU/Linux develops as a vendor.
30.7%
69.3%
Self-reported: 198Third-party: 447
Of all the CVEs published that affect products developed by Debian GNU/Linux, 1.9% are self-published by Debian GNU/Linux as a CNA.
98.1%
Self-published: 198Published by other CNAs: 10,016
Trends Over Time
The number and severity of CVEs published by Debian GNU/Linux over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 9, 2005
21 years ago
Most Recent CVE
Jun 10, 2026
44 days ago
Top CVEs
All CVEs published by Debian GNU/Linux as a CNA, regardless of affected vendor or product.
645 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-6271CRITICAL GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a cra | Sep 24, 2014 | 9.8 | 99 | YES | YES |
CVE-2022-0543CRITICAL It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code exec | Feb 18, 2022 | 10.0 | 98 | YES | YES |
CVE-2014-6278HIGH GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via | Sep 30, 2014 | 8.8 | 98 | YES | YES |
CVE-2016-10134CRITICAL SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids array parameter in latest.php. | Feb 17, 2017 | 9.8 | 86 | NO | YES |
CVE-2012-0209HIGH Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2012, contains an externally introduced m | Sep 25, 2012 | 7.5 | 81 | NO | YES |
CVE-2014-6277HIGH GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or caus | Sep 27, 2014 | 10.0 | 77 | NO | YES |
CVE-2013-1428MEDIUM Stack-based buffer overflow in the receive_tcppacket function in net_packet.c in tinc before 1.0.21 and 1.1 before 1.1pre7 allows remote authenticated peers to cause a denial of se | Apr 26, 2013 | 6.5 | 67 | NO | YES |
CVE-2012-0217HIGH The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos befor | Jun 12, 2012 | 7.2 | 65 | NO | YES |
CVE-2017-16995HIGH The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial of service (memory corruption) or possibly have unspecified | Dec 27, 2017 | 7.8 | 62 | NO | YES |
CVE-2005-3120CRITICAL Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian chara | Oct 17, 2005 | 9.8 | 53 | NO | YES |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA645 CVEs
8%
42%
37%
12%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local68 (10.5%)
Network265 (41.1%)
Unknown309 (47.9%)
Physical1 (0.2%)
Adjacent Network2 (0.3%)
Attack Complexity
Low300 (46.5%)
High36 (5.6%)
Unknown309 (47.9%)
User Interaction
None246 (38.1%)
Unknown309 (47.9%)
Required90 (14.0%)
Privileges Required
Low69 (10.7%)
High2 (0.3%)
None265 (41.1%)
Unknown309 (47.9%)
Exploit Exposure
Signals from CVEs in this cna scope (645 CVEs).
CISA KEV
3 CVEs
0.5% of CVEs· 85th percentile
Metasploit
13 CVEs
2.0% of CVEs· 91st percentile
Nuclei
4 CVEs
0.6% of CVEs· 77th percentile
ExploitDB
45 CVEs
7.0% of CVEs· 97th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Debian GNU/Linux as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Debian GNU/Linux as a CNA — matched by CVE ID, not by organization name.