Skip to content
Noroxi

BlueZ records

39 published records for vendor bluez.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
10
With a fix record
94.9%
Median publish → KEV
No record has entered KEV

All records

39 records
  • src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string lengt

    CriticalCVSS 9.8No exploitEPSS 4%

    bluez · bluez-libsJul 7, 2008

  • CVE-2024-8805
    36Monitor

    BlueZ HID over GATT Profile Improper Access Control Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 2%

    bluez · bluezNov 22, 2024

  • CVE-2022-0204
    36Monitor

    A heap overflow vulnerability was found in bluez in versions prior to 5.63.

    HighCVSS 8.8No exploitEPSS 2%

    bluez · bluezMar 10, 2022

  • An issue was discovered in gatt-database.c in BlueZ 5.61.

    CriticalCVSS 9.1No exploitEPSS 2%

    bluez · bluezNov 4, 2021

  • In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c.

    HighCVSS 8.6No exploitEPSS 4%

    bluez · bluezOct 14, 2020

  • CVE-2019-8922
    35Monitor

    A heap-based buffer overflow was discovered in bluetoothd in BlueZ through 5.48.

    HighCVSS 8.8No exploitEPSS 2%

    bluez · bluezNov 29, 2021

  • BlueZ before 5.59 allows physically proximate attackers to obtain sensitive information because profiles/audio/avrcp.c does not validate par

    HighCVSS 8.8No exploitEPSS 1%

    bluez · bluezSep 2, 2022

  • BlueZ before 5.59 allows physically proximate attackers to cause a denial of service because malformed and invalid capabilities can be proce

    HighCVSS 8.8No exploitEPSS 1%

    bluez · bluezSep 2, 2022

  • BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability

    HighCVSS 8.0No exploitEPSS 2%

    bluez · bluezMay 2, 2024

  • BlueZ Audio Profile AVRCP Stack-based Buffer Overflow Remote Code Execution Vulnerability

    HighCVSS 8.0No exploitEPSS 2%

    bluez · bluezMay 2, 2024

  • BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability

    HighCVSS 8.0No exploitEPSS 1%

    bluez · bluezMay 2, 2024

  • BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability

    HighCVSS 8.0No exploitEPSS 1%

    bluez · bluezMay 2, 2024

  • CVE-2016-9917
    31Monitor

    In BlueZ 5.42, a buffer overflow was observed in "read_n" function in "tools/hcidump.c" source file.

    HighCVSS 7.5No exploitEPSS 4%

    bluez · bluezDec 8, 2016

  • CVE-2016-7837
    31Monitor

    Buffer overflow in BlueZ 5.41 and earlier allows an attacker to execute arbitrary code via the parse_line function used in some userland uti

    HighCVSS 7.8No exploitEPSS 1%

    bluez · bluezJun 9, 2017

  • All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attac

    MediumCVSS 6.5Proof of conceptEPSS 8%

    bluez · bluezSep 12, 2017

  • Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access.

    MediumCVSS 6.5Proof of conceptEPSS 6%

    bluez · bluezNov 23, 2020

  • BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability

    HighCVSS 7.1No exploitEPSS 2%

    bluez · bluezMay 2, 2024

  • CVE-2020-0556
    28Monitor

    Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user to potentially enable escalation of pri

    HighCVSS 7.1No exploitEPSS 1%

    bluez · bluezMar 12, 2020

  • Improper buffer restrictions in BlueZ may allow an unauthenticated user to potentially enable denial of service via adjacent access.

    MediumCVSS 6.5Proof of conceptEPSS 2%

    bluez · bluezFeb 2, 2021

  • Memory leak in BlueZ

    MediumCVSS 6.5No exploitEPSS 1%

    bluez · bluezNov 12, 2021

  • CVE-2019-8921
    26Monitor

    An issue was discovered in bluetoothd in BlueZ through 5.48.

    MediumCVSS 6.5No exploitEPSS 1%

    bluez · bluezNov 29, 2021

  • CVE-2021-3658
    26Monitor

    bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up.

    MediumCVSS 6.5No exploitEPSS 1%

    bluez · bluezMar 2, 2022

  • CVE-2016-9798
    22Monitor

    In BlueZ 5.42, a use-after-free was identified in "conf_opt" function in "tools/parser/l2cap.c" source file.

    MediumCVSS 5.3No exploitEPSS 4%

    bluez · bluezDec 3, 2016

  • CVE-2016-9797
    22Monitor

    In BlueZ 5.42, a buffer over-read was observed in "l2cap_dump" function in "tools/parser/l2cap.c" source file.

    MediumCVSS 5.3No exploitEPSS 4%

    bluez · bluezDec 3, 2016

  • CVE-2016-9802
    22Monitor

    In BlueZ 5.42, a buffer over-read was identified in "l2cap_packet" function in "monitor/packet.c" source file.

    MediumCVSS 5.3No exploitEPSS 3%

    bluez · bluezDec 3, 2016