Bluez

Vendor:

First CVE: Aug 12, 2005 · Active for 20 years

41
Total CVEs
More Total CVEs than 64% of tracked products
4.6
Avg CVEs / Year
Bottom 1%
6.6
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Bluez over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 12, 2005
20 years ago
Most Recent CVE
Nov 22, 2024
611 days ago

CVE Severity & Scoring

Bluez41 CVEs
All CVEs352,713 CVEs
LowMediumHighCritical
Attack Vector
Local4 (9.8%)
Network12 (29.3%)
Unknown2 (4.9%)
Physical0 (0.0%)
Adjacent Network23 (56.1%)
Attack Complexity
Low38 (92.7%)
High1 (2.4%)
Unknown2 (4.9%)
User Interaction
None30 (73.2%)
Unknown2 (4.9%)
Required9 (22.0%)
Privileges Required
Low6 (14.6%)
High0 (0.0%)
None33 (80.5%)
Unknown2 (4.9%)

Top CVEs

Signals from CVEs in this product scope (41 CVEs).

41 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access.
Nov 23, 20206.530NOYES
An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValue call.
Nov 4, 20219.129NONO
In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a denial of service or code execu
Oct 15, 20208.629NONO
BlueZ before 5.59 allows physically proximate attackers to cause a denial of service because malformed and invalid capabilities can be processed in profiles/audio/avdtp.c.
Sep 2, 20228.828NONO
BlueZ before 5.59 allows physically proximate attackers to obtain sensitive information because profiles/audio/avrcp.c does not validate params_len.
Sep 2, 20228.828NONO
BlueZ HID over GATT Profile Improper Access Control Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected
Nov 22, 20248.827NONO
All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information fro
Sep 12, 20176.526NONO
In BlueZ 5.42, an out-of-bounds read was identified in "packet_hexdump" function in "monitor/packet.c" source file. This issue can be triggered by processing a corrupted dump file
Dec 8, 20167.526NONO
In BlueZ 5.42, a buffer overflow was observed in "read_n" function in "tools/hcidump.c" source file. This issue can be triggered by processing a corrupted dump file and will result
Dec 8, 20167.526NONO
BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via
May 3, 20248.024NONO

Exploit Exposure

Signals from CVEs in this product scope (41 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
4.9% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (41 CVEs).

Media Mentions

Signals from CVEs in this product scope (41 CVEs).

Top CNAs Publishing CVEs For Bluez

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.7718.82.0%00
5.6676.61.1%00
5.6119.11.5%00
5.5816.51.1%00
5.42105.73.1%00
2.1817.52.4%00