Записи BlueZ
39 опубликованных записей вендора bluez.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 10
- С записью об исправлении
- 94,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer10
- CWE-125 Out-of-bounds Read5
- CWE-122 Heap-based Buffer Overflow3
- CWE-404 Improper Resource Shutdown or Release2
- CWE-416 Use After Free2
- CWE-863 Incorrect Authorization2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
39 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2008-2374Эксплойта нет | src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string lengtbluez · bluez-libs · CWE-1284 | Критическая9,8 | — | 4,3 % | 7 июл. 2008 г. |
36Наблюдать | CVE-2024-8805Эксплойта нет | BlueZ HID over GATT Profile Improper Access Control Remote Code Execution Vulnerabilitybluez · bluez · CWE-284 | Высокая8,8 | — | 2,0 % | 22 нояб. 2024 г. |
36Наблюдать | CVE-2022-0204Эксплойта нет | A heap overflow vulnerability was found in bluez in versions prior to 5.63.bluez · bluez · CWE-119 | Высокая8,8 | — | 1,8 % | 10 мар. 2022 г. |
36Наблюдать | CVE-2021-43400Эксплойта нет | An issue was discovered in gatt-database.c in BlueZ 5.61.bluez · bluez · CWE-416 | Критическая9,1 | — | 1,7 % | 4 нояб. 2021 г. |
35Наблюдать | CVE-2020-27153Эксплойта нет | In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c.bluez · bluez · CWE-415 | Высокая8,6 | — | 4,3 % | 14 окт. 2020 г. |
35Наблюдать | CVE-2019-8922Эксплойта нет | A heap-based buffer overflow was discovered in bluetoothd in BlueZ through 5.48.bluez · bluez · CWE-787 | Высокая8,8 | — | 1,5 % | 29 нояб. 2021 г. |
35Наблюдать | CVE-2022-39176Эксплойта нет | BlueZ before 5.59 allows physically proximate attackers to obtain sensitive information because profiles/audio/avrcp.c does not validate parbluez · bluez | Высокая8,8 | — | 0,7 % | 2 сент. 2022 г. |
35Наблюдать | CVE-2022-39177Эксплойта нет | BlueZ before 5.59 allows physically proximate attackers to cause a denial of service because malformed and invalid capabilities can be procebluez · bluez | Высокая8,8 | — | 0,7 % | 2 сент. 2022 г. |
33Наблюдать | CVE-2023-50229Эксплойта нет | BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerabilitybluez · bluez · CWE-122 | Высокая8,0 | — | 2,3 % | 2 мая 2024 г. |
32Наблюдать | CVE-2023-44431Эксплойта нет | BlueZ Audio Profile AVRCP Stack-based Buffer Overflow Remote Code Execution Vulnerabilitybluez · bluez · CWE-121 | Высокая8,0 | — | 1,6 % | 2 мая 2024 г. |
32Наблюдать | CVE-2023-50230Эксплойта нет | BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerabilitybluez · bluez · CWE-122 | Высокая8,0 | — | 1,5 % | 2 мая 2024 г. |
32Наблюдать | CVE-2023-27349Эксплойта нет | BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerabilitybluez · bluez · CWE-129 | Высокая8,0 | — | 1,4 % | 2 мая 2024 г. |
31Наблюдать | CVE-2016-9917Эксплойта нет | In BlueZ 5.42, a buffer overflow was observed in "read_n" function in "tools/hcidump.c" source file.bluez · bluez · CWE-119 | Высокая7,5 | — | 3,6 % | 8 дек. 2016 г. |
31Наблюдать | CVE-2016-7837Эксплойта нет | Buffer overflow in BlueZ 5.41 and earlier allows an attacker to execute arbitrary code via the parse_line function used in some userland utibluez · bluez · CWE-119 | Высокая7,8 | — | 0,6 % | 9 июн. 2017 г. |
28Наблюдать | CVE-2017-1000250Proof of concept | All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attacbluez · bluez · CWE-200 | Средняя6,5 | — | 7,8 % | 12 сент. 2017 г. |
28Наблюдать | CVE-2020-12352Proof of concept | Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access.bluez · bluez · CWE-909 | Средняя6,5 | — | 5,7 % | 23 нояб. 2020 г. |
28Наблюдать | CVE-2023-51596Эксплойта нет | BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerabilitybluez · bluez · CWE-122 | Высокая7,1 | — | 1,5 % | 2 мая 2024 г. |
28Наблюдать | CVE-2020-0556Эксплойта нет | Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user to potentially enable escalation of pribluez · bluez | Высокая7,1 | — | 1,0 % | 12 мар. 2020 г. |
27Наблюдать | CVE-2020-24490Proof of concept | Improper buffer restrictions in BlueZ may allow an unauthenticated user to potentially enable denial of service via adjacent access.bluez · bluez | Средняя6,5 | — | 2,2 % | 2 февр. 2021 г. |
26Наблюдать | CVE-2021-41229Эксплойта нет | Memory leak in BlueZbluez · bluez · CWE-400 | Средняя6,5 | — | 1,2 % | 12 нояб. 2021 г. |
26Наблюдать | CVE-2019-8921Эксплойта нет | An issue was discovered in bluetoothd in BlueZ through 5.48.bluez · bluez · CWE-345 | Средняя6,5 | — | 1,0 % | 29 нояб. 2021 г. |
26Наблюдать | CVE-2021-3658Эксплойта нет | bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up.bluez · bluez · CWE-863 | Средняя6,5 | — | 0,8 % | 2 мар. 2022 г. |
22Наблюдать | CVE-2016-9798Эксплойта нет | In BlueZ 5.42, a use-after-free was identified in "conf_opt" function in "tools/parser/l2cap.c" source file.bluez · bluez · CWE-416 | Средняя5,3 | — | 3,8 % | 3 дек. 2016 г. |
22Наблюдать | CVE-2016-9797Эксплойта нет | In BlueZ 5.42, a buffer over-read was observed in "l2cap_dump" function in "tools/parser/l2cap.c" source file.bluez · bluez · CWE-119 | Средняя5,3 | — | 3,7 % | 3 дек. 2016 г. |
22Наблюдать | CVE-2016-9802Эксплойта нет | In BlueZ 5.42, a buffer over-read was identified in "l2cap_packet" function in "monitor/packet.c" source file.bluez · bluez · CWE-119 | Средняя5,3 | — | 3,3 % | 3 дек. 2016 г. |
- CVE-2008-237440В плане
src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string lengt
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %bluez · bluez-libs7 июл. 2008 г.
- CVE-2024-880536Наблюдать
BlueZ HID over GATT Profile Improper Access Control Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %bluez · bluez22 нояб. 2024 г.
- CVE-2022-020436Наблюдать
A heap overflow vulnerability was found in bluez in versions prior to 5.63.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %bluez · bluez10 мар. 2022 г.
- CVE-2021-4340036Наблюдать
An issue was discovered in gatt-database.c in BlueZ 5.61.
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %bluez · bluez4 нояб. 2021 г.
- CVE-2020-2715335Наблюдать
In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c.
ВысокаяCVSS 8,6Эксплойта нетEPSS 4 %bluez · bluez14 окт. 2020 г.
- CVE-2019-892235Наблюдать
A heap-based buffer overflow was discovered in bluetoothd in BlueZ through 5.48.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %bluez · bluez29 нояб. 2021 г.
- CVE-2022-3917635Наблюдать
BlueZ before 5.59 allows physically proximate attackers to obtain sensitive information because profiles/audio/avrcp.c does not validate par
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %bluez · bluez2 сент. 2022 г.
- CVE-2022-3917735Наблюдать
BlueZ before 5.59 allows physically proximate attackers to cause a denial of service because malformed and invalid capabilities can be proce
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %bluez · bluez2 сент. 2022 г.
- CVE-2023-5022933Наблюдать
BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability
ВысокаяCVSS 8,0Эксплойта нетEPSS 2 %bluez · bluez2 мая 2024 г.
- CVE-2023-4443132Наблюдать
BlueZ Audio Profile AVRCP Stack-based Buffer Overflow Remote Code Execution Vulnerability
ВысокаяCVSS 8,0Эксплойта нетEPSS 2 %bluez · bluez2 мая 2024 г.
- CVE-2023-5023032Наблюдать
BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability
ВысокаяCVSS 8,0Эксплойта нетEPSS 1 %bluez · bluez2 мая 2024 г.
- CVE-2023-2734932Наблюдать
BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability
ВысокаяCVSS 8,0Эксплойта нетEPSS 1 %bluez · bluez2 мая 2024 г.
- CVE-2016-991731Наблюдать
In BlueZ 5.42, a buffer overflow was observed in "read_n" function in "tools/hcidump.c" source file.
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %bluez · bluez8 дек. 2016 г.
- CVE-2016-783731Наблюдать
Buffer overflow in BlueZ 5.41 and earlier allows an attacker to execute arbitrary code via the parse_line function used in some userland uti
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %bluez · bluez9 июн. 2017 г.
- CVE-2017-100025028Наблюдать
All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attac
СредняяCVSS 6,5Proof of conceptEPSS 8 %bluez · bluez12 сент. 2017 г.
- CVE-2020-1235228Наблюдать
Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access.
СредняяCVSS 6,5Proof of conceptEPSS 6 %bluez · bluez23 нояб. 2020 г.
- CVE-2023-5159628Наблюдать
BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability
ВысокаяCVSS 7,1Эксплойта нетEPSS 2 %bluez · bluez2 мая 2024 г.
- CVE-2020-055628Наблюдать
Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user to potentially enable escalation of pri
ВысокаяCVSS 7,1Эксплойта нетEPSS 1 %bluez · bluez12 мар. 2020 г.
- CVE-2020-2449027Наблюдать
Improper buffer restrictions in BlueZ may allow an unauthenticated user to potentially enable denial of service via adjacent access.
СредняяCVSS 6,5Proof of conceptEPSS 2 %bluez · bluez2 февр. 2021 г.
- CVE-2021-4122926Наблюдать
Memory leak in BlueZ
СредняяCVSS 6,5Эксплойта нетEPSS 1 %bluez · bluez12 нояб. 2021 г.
- CVE-2019-892126Наблюдать
An issue was discovered in bluetoothd in BlueZ through 5.48.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %bluez · bluez29 нояб. 2021 г.
- CVE-2021-365826Наблюдать
bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %bluez · bluez2 мар. 2022 г.
- CVE-2016-979822Наблюдать
In BlueZ 5.42, a use-after-free was identified in "conf_opt" function in "tools/parser/l2cap.c" source file.
СредняяCVSS 5,3Эксплойта нетEPSS 4 %bluez · bluez3 дек. 2016 г.
- CVE-2016-979722Наблюдать
In BlueZ 5.42, a buffer over-read was observed in "l2cap_dump" function in "tools/parser/l2cap.c" source file.
СредняяCVSS 5,3Эксплойта нетEPSS 4 %bluez · bluez3 дек. 2016 г.
- CVE-2016-980222Наблюдать
In BlueZ 5.42, a buffer over-read was identified in "l2cap_packet" function in "monitor/packet.c" source file.
СредняяCVSS 5,3Эксплойта нетEPSS 3 %bluez · bluez3 дек. 2016 г.