Bluez
Vendor:
First CVE: Aug 12, 2005 · Active for 20 years
41
Total CVEs
More Total CVEs than 64% of tracked products
4.6
Avg CVEs / Year
Bottom 1%
6.6
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Bluez over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 12, 2005
20 years ago
Most Recent CVE
Nov 22, 2024
611 days ago
CVE Severity & Scoring
Bluez41 CVEs
54%
39%
All CVEs352,713 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (9.8%)
Network12 (29.3%)
Unknown2 (4.9%)
Physical0 (0.0%)
Adjacent Network23 (56.1%)
Attack Complexity
Low38 (92.7%)
High1 (2.4%)
Unknown2 (4.9%)
User Interaction
None30 (73.2%)
Unknown2 (4.9%)
Required9 (22.0%)
Privileges Required
Low6 (14.6%)
High0 (0.0%)
None33 (80.5%)
Unknown2 (4.9%)
Top CVEs
Signals from CVEs in this product scope (41 CVEs).
41 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-12352MEDIUM Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access. | Nov 23, 2020 | 6.5 | 30 | NO | YES |
CVE-2021-43400CRITICAL An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValue call. | Nov 4, 2021 | 9.1 | 29 | NO | NO |
CVE-2020-27153HIGH In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a denial of service or code execu | Oct 15, 2020 | 8.6 | 29 | NO | NO |
CVE-2022-39177HIGH BlueZ before 5.59 allows physically proximate attackers to cause a denial of service because malformed and invalid capabilities can be processed in profiles/audio/avdtp.c. | Sep 2, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-39176HIGH BlueZ before 5.59 allows physically proximate attackers to obtain sensitive information because profiles/audio/avrcp.c does not validate params_len. | Sep 2, 2022 | 8.8 | 28 | NO | NO |
CVE-2024-8805HIGH BlueZ HID over GATT Profile Improper Access Control Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected | Nov 22, 2024 | 8.8 | 27 | NO | NO |
CVE-2017-1000250MEDIUM All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information fro | Sep 12, 2017 | 6.5 | 26 | NO | NO |
CVE-2016-9918HIGH In BlueZ 5.42, an out-of-bounds read was identified in "packet_hexdump" function in "monitor/packet.c" source file. This issue can be triggered by processing a corrupted dump file | Dec 8, 2016 | 7.5 | 26 | NO | NO |
CVE-2016-9917HIGH In BlueZ 5.42, a buffer overflow was observed in "read_n" function in "tools/hcidump.c" source file. This issue can be triggered by processing a corrupted dump file and will result | Dec 8, 2016 | 7.5 | 26 | NO | NO |
CVE-2023-27349HIGH BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via | May 3, 2024 | 8.0 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (41 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
4.9% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (41 CVEs).
Media Mentions
Signals from CVEs in this product scope (41 CVEs).
Top CNAs Publishing CVEs For Bluez
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.77 | 1 | 8.8 | 2.0% | 0 | 0 |
| 5.66 | 7 | 6.6 | 1.1% | 0 | 0 |
| 5.61 | 1 | 9.1 | 1.5% | 0 | 0 |
| 5.58 | 1 | 6.5 | 1.1% | 0 | 0 |
| 5.42 | 10 | 5.7 | 3.1% | 0 | 0 |
| 2.18 | 1 | 7.5 | 2.4% | 0 | 0 |