Bluez

Bluez

37 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 21.10.2022 11:15:09
  • Zuletzt bearbeitet 21.11.2024 07:19:56

A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function jlink_init of the file monitor/jlink.c of the component BlueZ. The manipulation leads to denial of service. It is recommended to app...

  • EPSS 0.02%
  • Veröffentlicht 17.10.2022 19:15:10
  • Zuletzt bearbeitet 21.11.2024 07:19:46

A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function read_50_controller_cap_complete of the file tools/mgmt-tester.c of the component BlueZ. The manipulation of the argument cap_len leads to null pointer ...

  • EPSS 0.05%
  • Veröffentlicht 02.09.2022 04:15:11
  • Zuletzt bearbeitet 21.11.2024 07:17:43

BlueZ before 5.59 allows physically proximate attackers to cause a denial of service because malformed and invalid capabilities can be processed in profiles/audio/avdtp.c.

  • EPSS 0.09%
  • Veröffentlicht 02.09.2022 04:15:11
  • Zuletzt bearbeitet 21.11.2024 07:17:43

BlueZ before 5.59 allows physically proximate attackers to obtain sensitive information because profiles/audio/avrcp.c does not validate params_len.

Exploit
  • EPSS 0.07%
  • Veröffentlicht 10.03.2022 17:44:55
  • Zuletzt bearbeitet 21.11.2024 06:38:08

A heap overflow vulnerability was found in bluez in versions prior to 5.63. An attacker with local network access could pass specially crafted files causing an application to halt or crash, leading to a denial of service.

  • EPSS 0.06%
  • Veröffentlicht 02.03.2022 23:15:08
  • Zuletzt bearbeitet 21.11.2024 06:22:05

bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to in...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 29.11.2021 08:15:07
  • Zuletzt bearbeitet 21.11.2024 04:50:39

A heap-based buffer overflow was discovered in bluetoothd in BlueZ through 5.48. There isn't any check on whether there is enough space in the destination buffer. The function simply appends all data passed to it. The values of all attributes that ar...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 29.11.2021 08:15:07
  • Zuletzt bearbeitet 21.11.2024 04:50:39

An issue was discovered in bluetoothd in BlueZ through 5.48. The vulnerability lies in the handling of a SVC_ATTR_REQ by the SDP implementation. By crafting a malicious CSTATE, it is possible to trick the server into returning more bytes than the buf...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 12.11.2021 23:15:08
  • Zuletzt bearbeitet 21.11.2024 06:25:50

BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which allocates memory which will always be hung in the singly linked list of cstates and will not be freed. This will cause a memory l...

  • EPSS 0.12%
  • Veröffentlicht 04.11.2021 23:15:10
  • Zuletzt bearbeitet 21.11.2024 06:29:10

An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValue call.