Search CVE reports
11 – 20 of 52 results
CVE-2023-27349
Medium priorityBlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via Bluetooth on affected installations of BlueZ....
1 affected package
bluez
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
bluez | Not affected | Fixed | Fixed | Fixed | Fixed |
CVE-2023-45866
Medium priorityBluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no...
1 affected package
bluez
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
bluez | Fixed | Fixed | Fixed | Fixed | Fixed |
CVE-2022-24695
Low priorityBluetooth Classic in Bluetooth Core Specification through 5.3 does not properly conceal device information for Bluetooth transceivers in Non-Discoverable mode. By conducting an efficient over-the-air attack, an attacker can fully...
1 affected package
bluez
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
bluez | Ignored | Ignored | Ignored | Ignored | Ignored |
CVE-2022-3637
Medium priorityA vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function jlink_init of the file monitor/jlink.c of the component BlueZ. The manipulation leads to denial of service. It...
1 affected package
bluez
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
bluez | Not affected | Not affected | Not affected | Not affected | Vulnerable |
CVE-2022-3563
Low priorityA vulnerability classified as problematic has been found in Linux Kernel. Affected is the function read_50_controller_cap_complete of the file tools/mgmt-tester.c of the component BlueZ. The manipulation of the argument cap_len...
1 affected package
bluez
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
bluez | Not affected | Fixed | Not affected | Not affected | Fixed |
CVE-2022-39177
Medium prioritySome fixes available 2 of 3
BlueZ before 5.59 allows physically proximate attackers to cause a denial of service because malformed and invalid capabilities can be processed in profiles/audio/avdtp.c.
1 affected package
bluez
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
bluez | Not affected | Not affected | Fixed | Fixed | Vulnerable |
CVE-2022-39176
Medium prioritySome fixes available 2 of 3
BlueZ before 5.59 allows physically proximate attackers to obtain sensitive information because profiles/audio/avrcp.c does not validate params_len.
1 affected package
bluez
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
bluez | Not affected | Not affected | Fixed | Fixed | Vulnerable |
CVE-2022-0204
Medium priorityA heap overflow vulnerability was found in bluez in versions prior to 5.63. An attacker with local network access could pass specially crafted files causing an application to halt or crash, leading to a denial of service.
1 affected package
bluez
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
bluez | — | Fixed | Fixed | Fixed | Fixed |
CVE-2019-8922
Medium prioritySome fixes available 1 of 2
A heap-based buffer overflow was discovered in bluetoothd in BlueZ through 5.48. There isn't any check on whether there is enough space in the destination buffer. The function simply appends all data passed to it. The values of...
1 affected package
bluez
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
bluez | Not affected | Not affected | Not affected | Fixed | Vulnerable |
CVE-2019-8921
Medium prioritySome fixes available 1 of 2
An issue was discovered in bluetoothd in BlueZ through 5.48. The vulnerability lies in the handling of a SVC_ATTR_REQ by the SDP implementation. By crafting a malicious CSTATE, it is possible to trick the server into returning...
1 affected package
bluez
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
bluez | Not affected | Not affected | Not affected | Fixed | Vulnerable |