Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

BlueZ — Vulnerabilities & Security Advisories 20

All 20 CVE vulnerabilities found in BlueZ, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of vulnerabilities affecting BlueZ, the official Linux kernel Bluetooth protocol stack, categorized under general wireless protocol weaknesses. It collects a wide spectrum of security issues ranging from remote code execution and denial of service to information disclosure and privilege escalation flaws that have been publicly disclosed or patched. The database currently covers vulnerability records spanning from the initial public release of the stack through to recent updates, ensuring a historical perspective on the product's security posture. By navigating this resource, users can systematically track vendor advisories and patch cycles associated with specific versions of BlueZ. Additionally, researchers and security professionals can analyze the evolution of particular weakness classes within the context of Bluetooth implementations to identify recurring patterns or systemic design flaws. The page also serves as a detailed lookup tool for understanding the complete vulnerability history of the product, allowing stakeholders to assess risk over time. This centralized view facilitates better threat modeling and compliance auditing by providing clear insights into past incidents and their resolutions without requiring manual cross-referencing of multiple sources. The data is structured to support both high-level trend analysis and deep-dive technical reviews, ensuring that all relevant security events are accessible for thorough investigation.

Vendor: BlueZ Project

CVE IDTitleCVSSSeverityPublished
CVE-2024-8805 BlueZ HID over GATT Profile Improper Access Control Remote Code Execution Vulnerability CWE-284 8.8 -2024-11-22
CVE-2023-51596 BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability CWE-122 8.0 -2024-05-03
CVE-2023-51594 BlueZ OBEX Library Out-Of-Bounds Read Information Disclosure Vulnerability CWE-125 5.7 -2024-05-03
CVE-2023-51592 BlueZ Audio Profile AVRCP parse_media_folder Out-Of-Bounds Read Information Disclosure Vulnerability CWE-125 5.7 -2024-05-03
CVE-2023-51589 BlueZ Audio Profile AVRCP parse_media_element Out-Of-Bounds Read Information Disclosure Vulnerability CWE-125 5.7 -2024-05-03
CVE-2023-51580 BlueZ Audio Profile AVRCP avrcp_parse_attribute_list Out-Of-Bounds Read Information Disclosure Vulnerability CWE-125 5.7 -2024-05-03
CVE-2023-50230 BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability CWE-122 8.0 -2024-05-03
CVE-2023-50229 BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability CWE-122 8.0 -2024-05-03
CVE-2023-44431 BlueZ Audio Profile AVRCP Stack-based Buffer Overflow Remote Code Execution Vulnerability CWE-121 8.0 -2024-05-03
CVE-2023-27349 BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability CWE-129 8.0 -2024-05-03
CVE-2022-0204 BlueZ 输入验证错误漏洞 CWE-119 6.5 -2022-03-09
CVE-2021-3658 bluez 安全漏洞 CWE-863 4.3 -2022-03-02
CVE-2021-41229 Memory leak in BlueZ CWE-400 4.3 Medium2021-11-12
CVE-2021-3588 memory contents disclosure in cli_feat_read_cb CWE-788 3.3 Low2021-06-10
CVE-2021-0129 BlueZ 安全漏洞 5.7 -2021-06-09
CVE-2020-12352 Linux kernel 信息泄露漏洞 6.5 -2020-11-23
CVE-2020-12351 Linux kernel 输入验证错误漏洞 8.8 -2020-11-23
CVE-2020-0556 BlueZ 访问控制错误漏洞 8.3 -2020-03-12
CVE-2018-10910 Bluez 权限许可和访问控制问题漏洞 CWE-863 4.3 -2019-01-28
CVE-2016-7837 BlueZ 缓冲区错误漏洞 8.8 -2017-06-09

All 20 known CVE vulnerabilities affecting BlueZ with full Chinese analysis, references, and POCs where available.