Bluez

Bluez

37 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Published 21.10.2022 11:15:09
  • Last modified 21.11.2024 07:19:56

A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function jlink_init of the file monitor/jlink.c of the component BlueZ. The manipulation leads to denial of service. It is recommended to app...

  • EPSS 0.02%
  • Published 17.10.2022 19:15:10
  • Last modified 21.11.2024 07:19:46

A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function read_50_controller_cap_complete of the file tools/mgmt-tester.c of the component BlueZ. The manipulation of the argument cap_len leads to null pointer ...

  • EPSS 0.05%
  • Published 02.09.2022 04:15:11
  • Last modified 21.11.2024 07:17:43

BlueZ before 5.59 allows physically proximate attackers to cause a denial of service because malformed and invalid capabilities can be processed in profiles/audio/avdtp.c.

  • EPSS 0.09%
  • Published 02.09.2022 04:15:11
  • Last modified 21.11.2024 07:17:43

BlueZ before 5.59 allows physically proximate attackers to obtain sensitive information because profiles/audio/avrcp.c does not validate params_len.

Exploit
  • EPSS 0.07%
  • Published 10.03.2022 17:44:55
  • Last modified 21.11.2024 06:38:08

A heap overflow vulnerability was found in bluez in versions prior to 5.63. An attacker with local network access could pass specially crafted files causing an application to halt or crash, leading to a denial of service.

  • EPSS 0.06%
  • Published 02.03.2022 23:15:08
  • Last modified 21.11.2024 06:22:05

bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to in...

Exploit
  • EPSS 0.07%
  • Published 29.11.2021 08:15:07
  • Last modified 21.11.2024 04:50:39

A heap-based buffer overflow was discovered in bluetoothd in BlueZ through 5.48. There isn't any check on whether there is enough space in the destination buffer. The function simply appends all data passed to it. The values of all attributes that ar...

Exploit
  • EPSS 0.03%
  • Published 29.11.2021 08:15:07
  • Last modified 21.11.2024 04:50:39

An issue was discovered in bluetoothd in BlueZ through 5.48. The vulnerability lies in the handling of a SVC_ATTR_REQ by the SDP implementation. By crafting a malicious CSTATE, it is possible to trick the server into returning more bytes than the buf...

Exploit
  • EPSS 0.03%
  • Published 12.11.2021 23:15:08
  • Last modified 21.11.2024 06:25:50

BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which allocates memory which will always be hung in the singly linked list of cstates and will not be freed. This will cause a memory l...

  • EPSS 0.12%
  • Published 04.11.2021 23:15:10
  • Last modified 21.11.2024 06:29:10

An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValue call.