Dpkg

Vendor:

First CVE: Mar 15, 2010 · Active for 16 years

14
Total CVEs
More Total CVEs than 91% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Dpkg over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 15, 2010
16 years ago
Most Recent CVE
Mar 7, 2026
139 days ago

CVE Severity & Scoring

Dpkg14 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network4 (28.6%)
Unknown10 (71.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (28.6%)
High0 (0.0%)
Unknown10 (71.4%)
User Interaction
None4 (28.6%)
Unknown10 (71.4%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None4 (28.6%)
Unknown10 (71.4%)

Top CVEs

Signals from CVEs in this product scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU patch program and does not offer a protection mechanism for blank-indented diff hunks, which allows remote attack
Apr 26, 20179.834NONO
Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extractin
May 26, 20229.827NONO
Off-by-one error in the extracthalf function in dpkg-deb/extract.c in the dpkg-deb component in Debian dpkg 1.16.x before 1.16.17 and 1.17.x before 1.17.26 allows remote attackers
Dec 3, 20157.527NONO
It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compress
Mar 7, 20267.526NONO
It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which is documented as being a safe op
Jul 1, 20258.226NONO
Directory traversal vulnerability in dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via directory traversal sequences
Jan 11, 20116.822NONO
dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via a symlink attack on unspecified files in the .pc directory.
Jan 11, 20116.821NONO
Directory traversal vulnerability in the dpkg-source component in dpkg before 1.14.29 allows remote attackers to modify arbitrary files via a crafted Debian source archive.
Mar 15, 20105.821NONO
dpkg 1.9.21 does not properly reset the metadata of a file during replacement of the file in a package upgrade, which might allow local users to gain privileges by creating a hard
Jun 8, 20107.220NONO
Multiple format string vulnerabilities in the parse_error_msg function in parsehelp.c in dpkg before 1.17.22 allow remote attackers to cause a denial of service (crash) and possibl
Jan 20, 20156.819NONO

Exploit Exposure

Signals from CVEs in this product scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (14 CVEs).

Media Mentions

Signals from CVEs in this product scope (14 CVEs).

Top CNAs Publishing CVEs For Dpkg

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.9.927.43.7%00
1.9.827.43.7%00
1.9.727.43.7%00
1.9.419.84.6%00
1.9.327.43.7%00
1.9.2166.92.6%00
1.9.2056.83.1%00
1.9.227.43.7%00
1.9.1956.83.1%00
1.9.1827.43.7%00
1.9.1727.43.7%00
1.9.1627.43.7%00
1.9.1527.43.7%00
1.9.1427.43.7%00
1.9.1327.43.7%00
1.9.1227.43.7%00
1.9.1127.43.7%00
1.9.1027.43.7%00
1.9.127.43.7%00
1.9.019.84.6%00