Advanced Package Tool
Vendor:
First CVE: Apr 16, 2009 · Active for 17 years
21
Total CVEs
More Total CVEs than 94% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
5.4
Avg CVSS
Higher Avg CVSS than 14% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Advanced Package Tool over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 16, 2009
17 years ago
Most Recent CVE
Dec 10, 2020
2,052 days ago
CVE Severity & Scoring
Advanced Package Tool21 CVEs
33%
38%
29%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local2 (9.5%)
Network4 (19.0%)
Unknown15 (71.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (9.5%)
High4 (19.0%)
Unknown15 (71.4%)
User Interaction
None5 (23.8%)
Unknown15 (71.4%)
Required1 (4.8%)
Privileges Required
Low1 (4.8%)
High1 (4.8%)
None4 (19.0%)
Unknown15 (71.4%)
Top CVEs
Signals from CVEs in this product scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-3462HIGH Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to r | Jan 28, 2019 | 8.1 | 35 | NO | NO |
CVE-2016-1252MEDIUM The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1ubuntu2.17, in Ubuntu 16.04 LTS before 1.2.15ubuntu0.2, and | Dec 5, 2017 | 5.9 | 30 | NO | YES |
CVE-2009-1358HIGH apt-get in apt before 0.7.21 does not check for the correct error code from gpgv, which causes apt to treat a repository as valid even when it has been signed with a key that has b | Apr 21, 2009 | 10.0 | 26 | NO | NO |
CVE-2009-1300HIGH apt 0.7.20 does not check when the date command returns an "invalid date" error, which can prevent apt from loading security updates in time zones for which DST occurs at midnight. | Apr 16, 2009 | 10.0 | 25 | NO | NO |
CVE-2014-6273MEDIUM Buffer overflow in the HTTP transport code in apt-get in APT 1.0.1 and earlier allows man-in-the-middle attackers to cause a denial of service (crash) or possibly execute arbitrary | Sep 30, 2014 | 6.8 | 24 | NO | NO |
CVE-2018-0501MEDIUM The mirror:// method implementation in Advanced Package Tool (APT) 1.6.x before 1.6.4 and 1.7.x before 1.7.0~alpha3 mishandles gpg signature verification for the InRelease file of | Aug 21, 2018 | 5.9 | 22 | NO | NO |
CVE-2014-0490HIGH The apt-get download command in APT before 1.0.9 does not properly validate signatures for packages, which allows remote attackers to execute arbitrary code via a crafted package. | Nov 3, 2014 | 7.5 | 22 | NO | NO |
CVE-2020-27350MEDIUM APT had several integer overflows and underflows while parsing .deb packages, aka GHSL-2020-168 GHSL-2020-169, in files apt-pkg/contrib/extracttar.cc, apt-pkg/deb/debfile.cc, and a | Dec 10, 2020 | 5.7 | 21 | NO | NO |
CVE-2014-0489HIGH APT before 1.0.9, when the Acquire::GzipIndexes option is enabled, does not validate checksums, which allows remote attackers to execute arbitrary code via a crafted package. | Nov 3, 2014 | 7.5 | 20 | NO | NO |
CVE-2014-0487HIGH APT before 1.0.9 does not verify downloaded files if they have been modified as indicated using the If-Modified-Since header, which has unspecified impact and attack vectors. | Nov 3, 2014 | 7.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (21 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.8% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (21 CVEs).
Media Mentions
Signals from CVEs in this product scope (21 CVEs).
Top CNAs Publishing CVEs For Advanced Package Tool
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.7.0 | 1 | 5.9 | 0.9% | 0 | 0 |
| 1.0.8 | 1 | 3.6 | 0.4% | 0 | 0 |
| 1.0.7 | 4 | 7.3 | 2.8% | 0 | 0 |
| 1.0.6 | 1 | 7.5 | 3.6% | 0 | 0 |
| 1.0.5 | 2 | 7.5 | 3.6% | 0 | 0 |
| 1.0.4 | 1 | 7.5 | 3.6% | 0 | 0 |
| 1.0.3 | 4 | 7.3 | 2.8% | 0 | 0 |
| 0.8.16 | 2 | 3.2 | 0.9% | 0 | 0 |
| 0.8.15.9 | 2 | 2.6 | 2.0% | 0 | 0 |
| 0.8.15.8 | 2 | 2.6 | 2.0% | 0 | 0 |
| 0.8.15.7 | 2 | 2.6 | 2.0% | 0 | 0 |
| 0.8.15.6 | 2 | 2.6 | 2.0% | 0 | 0 |
| 0.8.15.10 | 2 | 2.6 | 2.0% | 0 | 0 |
| 0.8.15.1 | 2 | 2.6 | 2.0% | 0 | 0 |
| 0.8.15 | 2 | 2.6 | 2.0% | 0 | 0 |
| 0.8.14.1 | 2 | 2.6 | 2.0% | 0 | 0 |
| 0.8.14 | 2 | 2.6 | 2.0% | 0 | 0 |
| 0.8.13.2 | 2 | 2.6 | 2.0% | 0 | 0 |
| 0.8.13.1 | 2 | 2.6 | 2.0% | 0 | 0 |
| 0.8.13 | 2 | 2.6 | 2.0% | 0 | 0 |