CVEs we hold for Debian
Records whose assigning authority named Debian as the affected vendor. Newest identifiers first, capped at 200.
CVE-2022-1664directory traversal for in-place extracts with untrusted v2 and v3 source packages with debian.tarDebian dpkg
CVE-2018-5735Backport of the fix for CVE-2017-3137 leads to assertion failure in validator.c:1858Debian BIND9
CVE-2017-0359diffoscope writes to arbitrary locations on disk based on the contents of an untrusted archiveDebian diffoscope
32 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.