Deepin maintains a modestly represented portfolio centered on its desktop environment and system utilities, serving users across Linux distributions. The recurring vulnerability exposure concentrates in file-handling and access-control mechanisms—including symlink-following, path traversal, race conditions, and missing authorization checks—that characterize user-facing system tools and desktop components where privilege boundaries and filesystem operations intersect. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Deepin over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-7622HIGH dde-daemon, the daemon process of DDE (Deepin Desktop Environment) 15.0 through 15.3, runs with root privileges and hardly does anything to identify the user who calls the function | Apr 10, 2017 | 8.8 | 27 | NO | NO |
CVE-2023-50255HIGH Deepin-Compressor is the default archive manager of Deepin Linux OS. Prior to 5.12.21, there's a path traversal vulnerability in deepin-compressor that can be exploited to achieve | Dec 27, 2023 | 7.8 | 26 | NO | NO |
CVE-2023-50254HIGH Deepin Linux's default document reader `deepin-reader` software suffers from a serious vulnerability in versions prior to 6.0.7 due to a design flaw that leads to remote command ex | Dec 22, 2023 | 7.8 | 25 | NO | NO |
CVE-2019-13226HIGH deepin-clone before 1.1.3 uses a predictable path /tmp/.deepin-clone/mount/<block-dev-basename> in the Helper::temporaryMountDevice() function to temporarily mount a file system as | Jul 4, 2019 | 7.0 | 22 | NO | NO |
CVE-2019-13229MEDIUM deepin-clone before 1.1.3 uses a fixed path /tmp/partclone.log in the Helper::getPartitionSizeInfo() function to write a log file as root, and follows symlinks there. An unprivileg | Jul 4, 2019 | 5.5 | 19 | NO | NO |
CVE-2019-13227MEDIUM In GUI mode, deepin-clone before 1.1.3 creates a log file at the fixed path /tmp/.deepin-clone.log as root, and follows symlinks there. An unprivileged user can prepare a symlink a | Jul 4, 2019 | 5.5 | 19 | NO | NO |
CVE-2019-13228MEDIUM deepin-clone before 1.1.3 uses a fixed path /tmp/repo.iso in the BootDoctor::fix() function to download an ISO file, and follows symlinks there. An unprivileged user can prepare a | Jul 4, 2019 | 4.7 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Deepin.
Media articles that mention a CVE ID that affects a product developed by Deepin — matched by CVE ID, not by vendor name.