Search CVE reports


Toggle filters

51 – 60 of 66 results


CVE-2017-1000250

High priority
Fixed

All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd process memory....

1 affected package

bluez

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bluez — — — — —
Show less packages

CVE-2016-7837

Low priority

Some fixes available 2 of 4

Buffer overflow in BlueZ 5.41 and earlier allows an attacker to execute arbitrary code via the parse_line function used in some userland utilities.

1 affected package

bluez

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bluez — — — — Not affected
Show less packages

CVE-2016-9918

Negligible priority
Vulnerable

In BlueZ 5.42, an out-of-bounds read was identified in "packet_hexdump" function in "monitor/packet.c" source file. This issue can be triggered by processing a corrupted dump file and will result in btmon crash.

1 affected package

bluez

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bluez Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2016-9917

Negligible priority
Vulnerable

In BlueZ 5.42, a buffer overflow was observed in "read_n" function in "tools/hcidump.c" source file. This issue can be triggered by processing a corrupted dump file and will result in hcidump crash.

1 affected package

bluez

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bluez Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2016-9804

Negligible priority
Vulnerable

In BlueZ 5.42, a buffer overflow was observed in "commands_dump" function in "tools/parser/csr.c" source file. The issue exists because "commands" array is overflowed by supplied parameter due to lack of boundary checks on size of...

1 affected package

bluez

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bluez Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2016-9803

Negligible priority
Vulnerable

In BlueZ 5.42, an out-of-bounds read was observed in "le_meta_ev_dump" function in "tools/parser/hci.c" source file. This issue exists because 'subevent' (which is used to read correct element from 'ev_le_meta_str' array) is overflowed.

1 affected package

bluez

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bluez Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2016-9802

Negligible priority
Vulnerable

In BlueZ 5.42, a buffer over-read was identified in "l2cap_packet" function in "monitor/packet.c" source file. This issue can be triggered by processing a corrupted dump file and will result in btmon crash.

1 affected package

bluez

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bluez Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2016-9801

Negligible priority
Vulnerable

In BlueZ 5.42, a buffer overflow was observed in "set_ext_ctrl" function in "tools/parser/l2cap.c" source file when processing corrupted dump file.

1 affected package

bluez

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bluez Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2016-9800

Negligible priority
Vulnerable

In BlueZ 5.42, a buffer overflow was observed in "pin_code_reply_dump" function in "tools/parser/hci.c" source file. The issue exists because "pin" array is overflowed by supplied parameter due to lack of boundary checks on size...

1 affected package

bluez

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bluez Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2016-9799

Negligible priority
Vulnerable

In BlueZ 5.42, a buffer overflow was observed in "pklg_read_hci" function in "btsnoop.c" source file. This issue can be triggered by processing a corrupted dump file and will result in btmon crash.

1 affected package

bluez

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bluez Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages