Количество 15
Количество 15

CVE-2023-27349
BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device. The specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-19908.

CVE-2023-27349
BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device. The specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-19908.

CVE-2023-27349
BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device. The specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-19908.
CVE-2023-27349
BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Co ...

SUSE-SU-2023:2613-1
Security update for bluez

SUSE-SU-2023:2605-1
Security update for bluez

SUSE-SU-2023:2562-1
Security update for bluez

SUSE-SU-2023:2546-1
Security update for bluez

SUSE-SU-2023:2545-1
Security update for bluez

SUSE-SU-2023:2533-1
Security update for bluez

ROS-20240918-07
Уязвимость bluez
GHSA-r3vg-5hjq-528v
BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device. The specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-19908.

BDU:2024-01454
Уязвимость реализации протокола AVRCP стека протоколов Bluetooth для ОС Linux BlueZ, позволяющая нарушителю выполнить произвольный код с правами root
ELSA-2025-4043
ELSA-2025-4043: bluez security update (MODERATE)
ELSA-2024-9413
ELSA-2024-9413: bluez security update (MODERATE)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2023-27349 BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device. The specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-19908. | CVSS3: 7.1 | 7% Низкий | около 1 года назад |
![]() | CVE-2023-27349 BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device. The specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-19908. | CVSS3: 7.1 | 7% Низкий | около 1 года назад |
![]() | CVE-2023-27349 BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device. The specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-19908. | CVSS3: 7.1 | 7% Низкий | около 1 года назад |
CVE-2023-27349 BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Co ... | CVSS3: 7.1 | 7% Низкий | около 1 года назад | |
![]() | SUSE-SU-2023:2613-1 Security update for bluez | 7% Низкий | около 2 лет назад | |
![]() | SUSE-SU-2023:2605-1 Security update for bluez | 7% Низкий | около 2 лет назад | |
![]() | SUSE-SU-2023:2562-1 Security update for bluez | 7% Низкий | около 2 лет назад | |
![]() | SUSE-SU-2023:2546-1 Security update for bluez | 7% Низкий | около 2 лет назад | |
![]() | SUSE-SU-2023:2545-1 Security update for bluez | 7% Низкий | около 2 лет назад | |
![]() | SUSE-SU-2023:2533-1 Security update for bluez | 7% Низкий | около 2 лет назад | |
![]() | ROS-20240918-07 Уязвимость bluez | CVSS3: 7.1 | 7% Низкий | 9 месяцев назад |
GHSA-r3vg-5hjq-528v BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device. The specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-19908. | CVSS3: 7.1 | 7% Низкий | около 1 года назад | |
![]() | BDU:2024-01454 Уязвимость реализации протокола AVRCP стека протоколов Bluetooth для ОС Linux BlueZ, позволяющая нарушителю выполнить произвольный код с правами root | CVSS3: 7.1 | 7% Низкий | больше 2 лет назад |
ELSA-2025-4043 ELSA-2025-4043: bluez security update (MODERATE) | 2 месяца назад | |||
ELSA-2024-9413 ELSA-2024-9413: bluez security update (MODERATE) | 7 месяцев назад |
Уязвимостей на страницу