Debian / Dpkg
14 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-2219 | It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompre… | HIGH | 7.5 | Mar 7, 2026 |
| CVE-2025-6297 | dpkg-deb: Fix cleanup for control member with restricted directories | HIGH | 8.2 | Jul 1, 2025 |
| CVE-2022-1664 | directory traversal for in-place extracts with untrusted v2 and v3 source packages with debian.tar | CRITICAL | 9.8 | May 26, 2022 |
| CVE-2017-8283 | dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU patch program and does not offer a protection mechanism for blank-indented diff hunks, which… | CRITICAL | 9.8 | Apr 26, 2017 |
| CVE-2015-0860 | Off-by-one error in the extracthalf function in dpkg-deb/extract.c in the dpkg-deb component in Debian dpkg 1.16.x before 1.16.17 and 1.17.x before 1.17.26 all… | HIGH | 7.5 | Dec 3, 2015 |
| CVE-2015-0840 | The dpkg-source command in Debian dpkg before 1.16.16 and 1.17.x before 1.17.25 allows remote attackers to bypass signature verification via a crafted Debian s… | MEDIUM | 4.3 | Apr 13, 2015 |
| CVE-2014-8625 | Multiple format string vulnerabilities in the parse_error_msg function in parsehelp.c in dpkg before 1.17.22 allow remote attackers to cause a denial of servic… | MEDIUM | 6.8 | Jan 20, 2015 |
| CVE-2014-3227 | dpkg 1.15.9, 1.16.x before 1.16.14, and 1.17.x before 1.17.9 expect the patch program to be compliant with a need for the "C-style encoded filenames" feature,… | MEDIUM | 6.4 | May 30, 2014 |
| CVE-2014-3127 | dpkg 1.15.9 on Debian squeeze introduces support for the "C-style encoded filenames" feature without recognizing that the squeeze patch program lacks this feat… | HIGH | 7.1 | May 14, 2014 |
| CVE-2014-0471 | Directory traversal vulnerability in the unpacking functionality in dpkg before 1.15.9, 1.16.x before 1.16.13, and 1.17.x before 1.17.8 allows remote attackers… | MEDIUM | 5.0 | Apr 30, 2014 |
| CVE-2011-0402 | dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via a symlink attack on unspecified files in the… | MEDIUM | 6.8 | Jan 11, 2011 |
| CVE-2010-1679 | Directory traversal vulnerability in dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via director… | MEDIUM | 6.8 | Jan 11, 2011 |
| CVE-2004-2768 | dpkg 1.9.21 does not properly reset the metadata of a file during replacement of the file in a package upgrade, which might allow local users to gain privilege… | HIGH | 7.2 | Jun 8, 2010 |
| CVE-2010-0396 | dpkg: path traversal issue | MEDIUM | 5.8 | Mar 12, 2010 |
Showing 1 to 14 of 14 CVEs