Dpkg
Vendor:
First CVE: Mar 15, 2010 · Active for 16 years
14
Total CVEs
More Total CVEs than 91% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Dpkg over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 15, 2010
16 years ago
Most Recent CVE
Mar 7, 2026
139 days ago
CVE Severity & Scoring
Dpkg14 CVEs
50%
36%
14%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network4 (28.6%)
Unknown10 (71.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (28.6%)
High0 (0.0%)
Unknown10 (71.4%)
User Interaction
None4 (28.6%)
Unknown10 (71.4%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None4 (28.6%)
Unknown10 (71.4%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-8283CRITICAL dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU patch program and does not offer a protection mechanism for blank-indented diff hunks, which allows remote attack | Apr 26, 2017 | 9.8 | 34 | NO | NO |
CVE-2022-1664CRITICAL Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extractin | May 26, 2022 | 9.8 | 27 | NO | NO |
CVE-2015-0860HIGH Off-by-one error in the extracthalf function in dpkg-deb/extract.c in the dpkg-deb component in Debian dpkg 1.16.x before 1.16.17 and 1.17.x before 1.17.26 allows remote attackers | Dec 3, 2015 | 7.5 | 27 | NO | NO |
CVE-2026-2219HIGH It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compress | Mar 7, 2026 | 7.5 | 26 | NO | NO |
CVE-2025-6297HIGH It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which is
documented as being a safe op | Jul 1, 2025 | 8.2 | 26 | NO | NO |
CVE-2010-1679MEDIUM Directory traversal vulnerability in dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via directory traversal sequences | Jan 11, 2011 | 6.8 | 22 | NO | NO |
CVE-2011-0402MEDIUM dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via a symlink attack on unspecified files in the .pc directory. | Jan 11, 2011 | 6.8 | 21 | NO | NO |
CVE-2010-0396MEDIUM Directory traversal vulnerability in the dpkg-source component in dpkg before 1.14.29 allows remote attackers to modify arbitrary files via a crafted Debian source archive. | Mar 15, 2010 | 5.8 | 21 | NO | NO |
CVE-2004-2768HIGH dpkg 1.9.21 does not properly reset the metadata of a file during replacement of the file in a package upgrade, which might allow local users to gain privileges by creating a hard | Jun 8, 2010 | 7.2 | 20 | NO | NO |
CVE-2014-8625MEDIUM Multiple format string vulnerabilities in the parse_error_msg function in parsehelp.c in dpkg before 1.17.22 allow remote attackers to cause a denial of service (crash) and possibl | Jan 20, 2015 | 6.8 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Dpkg
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.9.9 | 2 | 7.4 | 3.7% | 0 | 0 |
| 1.9.8 | 2 | 7.4 | 3.7% | 0 | 0 |
| 1.9.7 | 2 | 7.4 | 3.7% | 0 | 0 |
| 1.9.4 | 1 | 9.8 | 4.6% | 0 | 0 |
| 1.9.3 | 2 | 7.4 | 3.7% | 0 | 0 |
| 1.9.21 | 6 | 6.9 | 2.6% | 0 | 0 |
| 1.9.20 | 5 | 6.8 | 3.1% | 0 | 0 |
| 1.9.2 | 2 | 7.4 | 3.7% | 0 | 0 |
| 1.9.19 | 5 | 6.8 | 3.1% | 0 | 0 |
| 1.9.18 | 2 | 7.4 | 3.7% | 0 | 0 |
| 1.9.17 | 2 | 7.4 | 3.7% | 0 | 0 |
| 1.9.16 | 2 | 7.4 | 3.7% | 0 | 0 |
| 1.9.15 | 2 | 7.4 | 3.7% | 0 | 0 |
| 1.9.14 | 2 | 7.4 | 3.7% | 0 | 0 |
| 1.9.13 | 2 | 7.4 | 3.7% | 0 | 0 |
| 1.9.12 | 2 | 7.4 | 3.7% | 0 | 0 |
| 1.9.11 | 2 | 7.4 | 3.7% | 0 | 0 |
| 1.9.10 | 2 | 7.4 | 3.7% | 0 | 0 |
| 1.9.1 | 2 | 7.4 | 3.7% | 0 | 0 |
| 1.9.0 | 1 | 9.8 | 4.6% | 0 | 0 |