CVE Tools

Dpkg

14 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Dpkg, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Dpkg CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Dpkg CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-071
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-031
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 14 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical214%
  • High536%
  • Medium750%

Latest CVEs

The 14 most recently published vulnerabilities affecting Dpkg.

  1. CVE-2026-2219It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, ...7.5
  2. CVE-2025-6297dpkg-deb: Fix cleanup for control member with restricted directories8.2
  3. CVE-2022-1664directory traversal for in-place extracts with untrusted v2 and v3 source packages with debian.tar9.8
  4. CVE-2017-8283dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU patch program and does not offer a protection mechanism for blank-indented diff hunks, which allows remote attackers to conduct di...9.8
  5. CVE-2015-0860Off-by-one error in the extracthalf function in dpkg-deb/extract.c in the dpkg-deb component in Debian dpkg 1.16.x before 1.16.17 and 1.17.x before 1.17.26 allows remote attackers to execute arbitr...7.5
  6. CVE-2015-0840The dpkg-source command in Debian dpkg before 1.16.16 and 1.17.x before 1.17.25 allows remote attackers to bypass signature verification via a crafted Debian source control file (.dsc).4.3
  7. CVE-2014-8625Multiple format string vulnerabilities in the parse_error_msg function in parsehelp.c in dpkg before 1.17.22 allow remote attackers to cause a denial of service (crash) and possibly execute arbitra...6.8
  8. CVE-2014-3227dpkg 1.15.9, 1.16.x before 1.16.14, and 1.17.x before 1.17.9 expect the patch program to be compliant with a need for the "C-style encoded filenames" feature, but is supported in environments with ...6.4
  9. CVE-2014-3127dpkg 1.15.9 on Debian squeeze introduces support for the "C-style encoded filenames" feature without recognizing that the squeeze patch program lacks this feature, which triggers an interaction err...7.1
  10. CVE-2014-0471Directory traversal vulnerability in the unpacking functionality in dpkg before 1.15.9, 1.16.x before 1.16.13, and 1.17.x before 1.17.8 allows remote attackers to write arbitrary files via a crafte...5.0
  11. CVE-2011-0402dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via a symlink attack on unspecified files in the .pc directory.6.8
  12. CVE-2010-1679Directory traversal vulnerability in dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via directory traversal sequences in a patch for a...6.8
  13. CVE-2004-2768dpkg 1.9.21 does not properly reset the metadata of a file during replacement of the file in a package upgrade, which might allow local users to gain privileges by creating a hard link to a vulnera...7.2
  14. CVE-2010-0396Directory traversal vulnerability in the dpkg-source component in dpkg before 1.14.29 allows remote attackers to modify arbitrary files via a crafted Debian source archive.5.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store