Vulnerabilities > Bluez > Low

DATE CVE VULNERABILITY TITLE RISK
2022-03-02 CVE-2021-3658 Incorrect Authorization vulnerability in multiple products
bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up.
low complexity
bluez fedoraproject CWE-863
3.3
2021-06-10 CVE-2021-3588 Out-of-bounds Read vulnerability in Bluez
The cli_feat_read_cb() function in src/gatt-database.c does not perform bounds checks on the 'offset' variable before using it as an index into an array for reading.
local
low complexity
bluez CWE-125
3.3
2021-02-02 CVE-2020-24490 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Bluez
Improper buffer restrictions in BlueZ may allow an unauthenticated user to potentially enable denial of service via adjacent access.
low complexity
bluez CWE-119
3.3
2019-01-28 CVE-2018-10910 Incorrect Authorization vulnerability in multiple products
A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system.
local
low complexity
bluez canonical CWE-863
3.3
2017-09-12 CVE-2017-1000250 Information Exposure vulnerability in Bluez
All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd process memory.
low complexity
bluez CWE-200
3.3