Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Devscripts Devel Team

First CVE: Sep 4, 2009Active for: 17 yearsTotal CVEs: 14
40.2
VTI Score
Medium

Devscripts is a focused collection of utility scripts and tools used by Debian package developers and maintainers to automate common packaging workflows. Its recurring vulnerabilities center on input validation, race conditions, code injection, path traversal, and symlink-following issues that reflect the script-based nature of the tooling and its interaction with the filesystem and build environment. Defenders relying on devscripts should treat security advisories for the package seriously within development pipelines; current severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
2.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Devscripts Devel Team over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 4, 2009
16 years ago
Most Recent CVE
Sep 25, 2017
3,224 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-0211HIGH
debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to execute arbitrary code via a crafted tarball file name in the top-level directory
Jun 16, 20129.329NONO
CVE-2012-0210HIGH
debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to obtain system information and execute arbitrary code via the file name in a (1) .
Jun 16, 20129.329NONO
CVE-2009-2946HIGH
Eval injection vulnerability in scripts/uscan.pl before Rev 1984 in devscripts allows remote attackers to execute arbitrary Perl code via crafted pathnames on distribution servers
Sep 4, 20099.329NONO
CVE-2012-0212HIGH
debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to execute arbitrary code via shell metacharacters in the file name argument.
Jun 16, 20129.328NONO
CVE-2012-2240HIGH
scripts/dscverify.pl in devscripts before 2.12.3 allows remote attackers to execute arbitrary commands via unspecified vectors related to "arguments to external commands."
Oct 1, 20127.523NONO
CVE-2015-5705HIGH
Argument injection vulnerability in devscripts before 2.15.7 allows remote attackers to write to arbitrary files via a crafted symlink and crafted filename.
Sep 6, 20177.522NONO
CVE-2012-2242MEDIUM
scripts/dget.pl in devscripts before 2.10.73 allows remote attackers to execute arbitrary commands via a crafted (1) .dsc or (2) .changes file, related to "arguments to external co
Oct 1, 20126.822NONO
CVE-2015-5704HIGH
scripts/licensecheck.pl in devscripts before 2.15.7 allows local users to execute arbitrary shell commands.
Sep 25, 20177.821NONO
CVE-2013-7050MEDIUM
The get_main_source_dir function in scripts/uscan.pl in devscripts before 2.13.8, when using USCAN_EXCLUSION, allows remote attackers to execute arbitrary commands via shell metach
Dec 13, 20136.821NONO
CVE-2013-6888HIGH
Uscan in devscripts before 2.13.9 allows remote attackers to execute arbitrary code via a crafted tarball.
Jan 7, 20147.520NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
36%
57%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local1 (7.1%)
Network1 (7.1%)
Unknown12 (85.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (14.3%)
High0 (0.0%)
Unknown12 (85.7%)
User Interaction
None2 (14.3%)
Unknown12 (85.7%)
Required0 (0.0%)
Privileges Required
Low1 (7.1%)
High0 (0.0%)
None1 (7.1%)
Unknown12 (85.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Devscripts Devel Team.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Devscripts Devel Team — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Devscripts Devel Team's Products

View all 3 CNAs →

Top CWEs