BlueZ kayıtları
bluez üreticisine ait 39 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 10
- Düzeltme kaydı olan
- %94,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer10
- CWE-125 Out-of-bounds Read5
- CWE-122 Heap-based Buffer Overflow3
- CWE-404 Improper Resource Shutdown or Release2
- CWE-416 Use After Free2
- CWE-863 Incorrect Authorization2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
39 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2008-2374İstismar yok | src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string lengtbluez · bluez-libs · CWE-1284 | Kritik9,8 | — | %4,3 | 7 Tem 2008 |
36İzleyin | CVE-2024-8805İstismar yok | BlueZ HID over GATT Profile Improper Access Control Remote Code Execution Vulnerabilitybluez · bluez · CWE-284 | Yüksek8,8 | — | %2,0 | 22 Kas 2024 |
36İzleyin | CVE-2022-0204İstismar yok | A heap overflow vulnerability was found in bluez in versions prior to 5.63.bluez · bluez · CWE-119 | Yüksek8,8 | — | %1,8 | 10 Mar 2022 |
36İzleyin | CVE-2021-43400İstismar yok | An issue was discovered in gatt-database.c in BlueZ 5.61.bluez · bluez · CWE-416 | Kritik9,1 | — | %1,7 | 4 Kas 2021 |
35İzleyin | CVE-2020-27153İstismar yok | In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c.bluez · bluez · CWE-415 | Yüksek8,6 | — | %4,3 | 14 Eki 2020 |
35İzleyin | CVE-2019-8922İstismar yok | A heap-based buffer overflow was discovered in bluetoothd in BlueZ through 5.48.bluez · bluez · CWE-787 | Yüksek8,8 | — | %1,5 | 29 Kas 2021 |
35İzleyin | CVE-2022-39176İstismar yok | BlueZ before 5.59 allows physically proximate attackers to obtain sensitive information because profiles/audio/avrcp.c does not validate parbluez · bluez | Yüksek8,8 | — | %0,7 | 2 Eyl 2022 |
35İzleyin | CVE-2022-39177İstismar yok | BlueZ before 5.59 allows physically proximate attackers to cause a denial of service because malformed and invalid capabilities can be procebluez · bluez | Yüksek8,8 | — | %0,7 | 2 Eyl 2022 |
33İzleyin | CVE-2023-50229İstismar yok | BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerabilitybluez · bluez · CWE-122 | Yüksek8,0 | — | %2,3 | 2 May 2024 |
32İzleyin | CVE-2023-44431İstismar yok | BlueZ Audio Profile AVRCP Stack-based Buffer Overflow Remote Code Execution Vulnerabilitybluez · bluez · CWE-121 | Yüksek8,0 | — | %1,6 | 2 May 2024 |
32İzleyin | CVE-2023-50230İstismar yok | BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerabilitybluez · bluez · CWE-122 | Yüksek8,0 | — | %1,5 | 2 May 2024 |
32İzleyin | CVE-2023-27349İstismar yok | BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerabilitybluez · bluez · CWE-129 | Yüksek8,0 | — | %1,4 | 2 May 2024 |
31İzleyin | CVE-2016-9917İstismar yok | In BlueZ 5.42, a buffer overflow was observed in "read_n" function in "tools/hcidump.c" source file.bluez · bluez · CWE-119 | Yüksek7,5 | — | %3,6 | 8 Ara 2016 |
31İzleyin | CVE-2016-7837İstismar yok | Buffer overflow in BlueZ 5.41 and earlier allows an attacker to execute arbitrary code via the parse_line function used in some userland utibluez · bluez · CWE-119 | Yüksek7,8 | — | %0,6 | 9 Haz 2017 |
28İzleyin | CVE-2017-1000250Kavram kanıtı | All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attacbluez · bluez · CWE-200 | Orta6,5 | — | %7,8 | 12 Eyl 2017 |
28İzleyin | CVE-2020-12352Kavram kanıtı | Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access.bluez · bluez · CWE-909 | Orta6,5 | — | %5,7 | 23 Kas 2020 |
28İzleyin | CVE-2023-51596İstismar yok | BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerabilitybluez · bluez · CWE-122 | Yüksek7,1 | — | %1,5 | 2 May 2024 |
28İzleyin | CVE-2020-0556İstismar yok | Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user to potentially enable escalation of pribluez · bluez | Yüksek7,1 | — | %1,0 | 12 Mar 2020 |
27İzleyin | CVE-2020-24490Kavram kanıtı | Improper buffer restrictions in BlueZ may allow an unauthenticated user to potentially enable denial of service via adjacent access.bluez · bluez | Orta6,5 | — | %2,2 | 2 Şub 2021 |
26İzleyin | CVE-2021-41229İstismar yok | Memory leak in BlueZbluez · bluez · CWE-400 | Orta6,5 | — | %1,2 | 12 Kas 2021 |
26İzleyin | CVE-2019-8921İstismar yok | An issue was discovered in bluetoothd in BlueZ through 5.48.bluez · bluez · CWE-345 | Orta6,5 | — | %1,0 | 29 Kas 2021 |
26İzleyin | CVE-2021-3658İstismar yok | bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up.bluez · bluez · CWE-863 | Orta6,5 | — | %0,8 | 2 Mar 2022 |
22İzleyin | CVE-2016-9798İstismar yok | In BlueZ 5.42, a use-after-free was identified in "conf_opt" function in "tools/parser/l2cap.c" source file.bluez · bluez · CWE-416 | Orta5,3 | — | %3,8 | 3 Ara 2016 |
22İzleyin | CVE-2016-9797İstismar yok | In BlueZ 5.42, a buffer over-read was observed in "l2cap_dump" function in "tools/parser/l2cap.c" source file.bluez · bluez · CWE-119 | Orta5,3 | — | %3,7 | 3 Ara 2016 |
22İzleyin | CVE-2016-9802İstismar yok | In BlueZ 5.42, a buffer over-read was identified in "l2cap_packet" function in "monitor/packet.c" source file.bluez · bluez · CWE-119 | Orta5,3 | — | %3,3 | 3 Ara 2016 |
- CVE-2008-237440Planlayın
src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string lengt
KritikCVSS 9,8İstismar yokEPSS %4bluez · bluez-libs7 Tem 2008
- CVE-2024-880536İzleyin
BlueZ HID over GATT Profile Improper Access Control Remote Code Execution Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %2bluez · bluez22 Kas 2024
- CVE-2022-020436İzleyin
A heap overflow vulnerability was found in bluez in versions prior to 5.63.
YüksekCVSS 8,8İstismar yokEPSS %2bluez · bluez10 Mar 2022
- CVE-2021-4340036İzleyin
An issue was discovered in gatt-database.c in BlueZ 5.61.
KritikCVSS 9,1İstismar yokEPSS %2bluez · bluez4 Kas 2021
- CVE-2020-2715335İzleyin
In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c.
YüksekCVSS 8,6İstismar yokEPSS %4bluez · bluez14 Eki 2020
- CVE-2019-892235İzleyin
A heap-based buffer overflow was discovered in bluetoothd in BlueZ through 5.48.
YüksekCVSS 8,8İstismar yokEPSS %2bluez · bluez29 Kas 2021
- CVE-2022-3917635İzleyin
BlueZ before 5.59 allows physically proximate attackers to obtain sensitive information because profiles/audio/avrcp.c does not validate par
YüksekCVSS 8,8İstismar yokEPSS %1bluez · bluez2 Eyl 2022
- CVE-2022-3917735İzleyin
BlueZ before 5.59 allows physically proximate attackers to cause a denial of service because malformed and invalid capabilities can be proce
YüksekCVSS 8,8İstismar yokEPSS %1bluez · bluez2 Eyl 2022
- CVE-2023-5022933İzleyin
BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability
YüksekCVSS 8,0İstismar yokEPSS %2bluez · bluez2 May 2024
- CVE-2023-4443132İzleyin
BlueZ Audio Profile AVRCP Stack-based Buffer Overflow Remote Code Execution Vulnerability
YüksekCVSS 8,0İstismar yokEPSS %2bluez · bluez2 May 2024
- CVE-2023-5023032İzleyin
BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability
YüksekCVSS 8,0İstismar yokEPSS %1bluez · bluez2 May 2024
- CVE-2023-2734932İzleyin
BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability
YüksekCVSS 8,0İstismar yokEPSS %1bluez · bluez2 May 2024
- CVE-2016-991731İzleyin
In BlueZ 5.42, a buffer overflow was observed in "read_n" function in "tools/hcidump.c" source file.
YüksekCVSS 7,5İstismar yokEPSS %4bluez · bluez8 Ara 2016
- CVE-2016-783731İzleyin
Buffer overflow in BlueZ 5.41 and earlier allows an attacker to execute arbitrary code via the parse_line function used in some userland uti
YüksekCVSS 7,8İstismar yokEPSS %1bluez · bluez9 Haz 2017
- CVE-2017-100025028İzleyin
All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attac
OrtaCVSS 6,5Kavram kanıtıEPSS %8bluez · bluez12 Eyl 2017
- CVE-2020-1235228İzleyin
Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access.
OrtaCVSS 6,5Kavram kanıtıEPSS %6bluez · bluez23 Kas 2020
- CVE-2023-5159628İzleyin
BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability
YüksekCVSS 7,1İstismar yokEPSS %2bluez · bluez2 May 2024
- CVE-2020-055628İzleyin
Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user to potentially enable escalation of pri
YüksekCVSS 7,1İstismar yokEPSS %1bluez · bluez12 Mar 2020
- CVE-2020-2449027İzleyin
Improper buffer restrictions in BlueZ may allow an unauthenticated user to potentially enable denial of service via adjacent access.
OrtaCVSS 6,5Kavram kanıtıEPSS %2bluez · bluez2 Şub 2021
- CVE-2021-4122926İzleyin
Memory leak in BlueZ
OrtaCVSS 6,5İstismar yokEPSS %1bluez · bluez12 Kas 2021
- CVE-2019-892126İzleyin
An issue was discovered in bluetoothd in BlueZ through 5.48.
OrtaCVSS 6,5İstismar yokEPSS %1bluez · bluez29 Kas 2021
- CVE-2021-365826İzleyin
bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up.
OrtaCVSS 6,5İstismar yokEPSS %1bluez · bluez2 Mar 2022
- CVE-2016-979822İzleyin
In BlueZ 5.42, a use-after-free was identified in "conf_opt" function in "tools/parser/l2cap.c" source file.
OrtaCVSS 5,3İstismar yokEPSS %4bluez · bluez3 Ara 2016
- CVE-2016-979722İzleyin
In BlueZ 5.42, a buffer over-read was observed in "l2cap_dump" function in "tools/parser/l2cap.c" source file.
OrtaCVSS 5,3İstismar yokEPSS %4bluez · bluez3 Ara 2016
- CVE-2016-980222İzleyin
In BlueZ 5.42, a buffer over-read was identified in "l2cap_packet" function in "monitor/packet.c" source file.
OrtaCVSS 5,3İstismar yokEPSS %3bluez · bluez3 Ara 2016