cbcvebase.
CVE-2022-0204
published 2022-03-10

CVE-2022-0204: A heap overflow vulnerability was found in bluez in versions prior to 5.63. An attacker with local network access could pass specially crafted files causing an…

PriorityP348high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
1.81%
76.1th percentile
A heap overflow vulnerability was found in bluez in versions prior to 5.63. An attacker with local network access could pass specially crafted files causing an application to halt or crash, leading to a denial of service.

Affected

12 ranges
VendorProductVersion rangeFixed in
bluezbluez< 5.635.63
bluezbluez
bluezbluez>= 0 < 5.55-3.1+deb11u25.55-3.1+deb11u2
bluezbluez>= 0 < 5.64-15.64-1
bluezbluez>= 0 < 5.64-15.64-1
bluezbluez>= 0 < 5.64-15.64-1
bluezbluez>= 0 < 5.48-0ubuntu3.85.48-0ubuntu3.8
bluezbluez>= 0 < 5.53-0ubuntu3.55.53-0ubuntu3.5
bluezbluez>= 0 < 5.37-0ubuntu5.3+esm25.37-0ubuntu5.3+esm2
debianbluez< bluez 5.64-1 (bookworm)bluez 5.64-1 (bookworm)
debiandebian_linux
fedoraprojectfedora

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.8MEDIUMAV:A/AC:L/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.