CVE Tools

Apt

9 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Apt, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Apt CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Apt CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-051
2026-060
2026-070
2026-080
2026-090

Severity

How the 9 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical111%
  • High111%
  • Medium444%
  • Low333%

Latest CVEs

The 9 most recently published vulnerabilities affecting Apt.

  1. BDU:2026-06211Уязвимость функции PackageFromTask() программы для установки, обновления и удаления программных пакетов Apt, позволяющая нарушителю вызвать отказ в обслуживании5.5
  2. CVE-2020-27350apt integer wraparound5.7
  3. CVE-2020-3810Missing input validation in the ar/tar implementations of APT before version 2.1.2 could result in denial of service when processing specially crafted deb files.5.5
  4. CVE-2011-3374It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.3.7
  5. CVE-2019-3462Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execut...8.1
  6. CVE-2014-7206The changelog command in Apt before 1.0.9.2 allows local users to write to arbitrary files via a symlink attack on the changelog file.3.6
  7. CVE-2013-1051apt 0.8.16, 0.9.7, and possibly other versions does not properly handle InRelease files, which allows man-in-the-middle attackers to modify packages before installation via unknown vectors, possibl...4.3
  8. CVE-2012-0961Apt 0.8.16~exp5ubuntu13.x before 0.8.16~exp5ubuntu13.6, 0.8.16~exp12ubuntu10.x before 0.8.16~exp12ubuntu10.7, and 0.9.7.5ubuntu5.x before 0.9.7.5ubuntu5.2, as used in Ubuntu, uses world-readable pe...2.1
  9. CVE-2009-1358apt-get in apt before 0.7.21 does not check for the correct error code from gpgv, which causes apt to treat a repository as valid even when it has been signed with a key that has been revoked or ex...10.0

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store