How bad exactly is Debian stable security wise?

Debian has many insecurities out of the box, just to name a few: unrestricted access to su, IPv6 leakage of MAC address, and a firewall that accepts all incoming/outgoing traffic. Substantial hardening is needed to make Debian anywhere near secure. Debian has a security manual that explains many hardening measures.