CVE-2024-43766
published 2026-03-02CVE-2024-43766: In multiple functions of btm_ble_sec.cc, there is a possible unencrypted communication due to Invalid error handling. This could lead to remote…
PriorityP429medium6.5CVSS 3.1
AVAACLPRNUINSUCHINAN
EPSS
0.07%
0.0th percentile
In multiple functions of btm_ble_sec.cc, there is a possible unencrypted communication due to Invalid error handling. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | packages_modules_bluetooth | >= 14:0 < 14:2026-03-01 | 14:2026-03-01 |
| platform | packages_modules_bluetooth | >= 15:0 < 15:2026-03-01 | 15:2026-03-01 |
| platform | packages_modules_bluetooth | >= 16-qpr2-next:0 < 16-qpr2-next:2026-03-01 | 16-qpr2-next:2026-03-01 |
| platform | packages_modules_bluetooth | >= 16:0 < 16:2026-03-01 | 16:2026-03-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3qwq-pwj3-576h: In multiple functions of btm_ble_sec
ghsa_unreviewed·2026-03-02
CVE-2024-43766 [MEDIUM] CWE-319 GHSA-3qwq-pwj3-576h: In multiple functions of btm_ble_sec
In multiple functions of btm_ble_sec.cc, there is a possible unencrypted communication due to Invalid error handling. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2024-43766: In multiple functions of btm_ble_sec
osv·2026-03-01
CVE-2024-43766 CVE-2024-43766: In multiple functions of btm_ble_sec
In multiple functions of btm_ble_sec.cc, there is a possible unencrypted communication due to Invalid error handling. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
GHSA
Liferay Portal allows unrestricted upload of file in the style books component
ghsa·2025-08-23
CVE-2025-43766 [MEDIUM] CWE-434 Liferay Portal allows unrestricted upload of file in the style books component
Liferay Portal allows unrestricted upload of file in the style books component
The Liferay Portal 7.4.0 through 7.3.3.131, and Liferay DXP 2024.Q4.0, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows the upload of unrestricted files in the style books component that are processed within the environment enabling arbitrary code execution by attackers.
No detection rules found.
No public exploits indexed.
2026-03-02
Published