Platform Packages Modules Bluetooth vulnerabilities
119 known vulnerabilities affecting platform/packages_modules_bluetooth.
Total CVEs
119
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN119
Vulnerabilities
Page 3 of 6
CVE-2024-0030UNKNOWN≥ 14-next:0, < 14-next:2024-02-01≥ 13:0, < 13:2024-02-01+1 more2024-02-01
CVE-2024-0030 CVE-2024-0030: In btif_to_bta_response of btif_gatt_util
In btif_to_bta_response of btif_gatt_util.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-0031UNKNOWN≥ 14-next:0, < 14-next:2024-02-01≥ 13:0, < 13:2024-02-01+1 more2024-02-01
CVE-2024-0031 CVE-2024-0031: In attp_build_read_by_type_value_cmd of att_protocol
In attp_build_read_by_type_value_cmd of att_protocol.cc , there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-0016UNKNOWN≥ 13:0, < 13:2024-01-01≥ 14:0, < 14:2024-01-012024-01-01
CVE-2024-0016 CVE-2024-0016: In multiple locations, there is a possible out of bounds read due to a missing bounds check
In multiple locations, there is a possible out of bounds read due to a missing bounds check. This could lead to paired device information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-45781UNKNOWN≥ 14-next:0, < 14-next:2023-12-01≥ 13:0, < 13:2023-12-01+1 more2023-12-01
CVE-2023-45781 CVE-2023-45781: In parse_gap_data of utils
In parse_gap_data of utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-45866UNKNOWN≥ 14-next:0, < 14-next:2023-12-05≥ 13:0, < 13:2023-12-05+1 more2023-12-01
CVE-2023-45866 CVE-2023-45866: In multiple locations, there is a possible way to inject keystrokes due to improper input validation
In multiple locations, there is a possible way to inject keystrokes due to improper input validation. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-40078UNKNOWN≥ 14-next:0, < 14-next:2023-12-01≥ 14:0, < 14:2023-12-012023-12-01
CVE-2023-40078 CVE-2023-40078: In a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder
In a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-40090UNKNOWN≥ 13:0, < 13:2023-12-01≥ 14:0, < 14:2023-12-012023-12-01
CVE-2023-40090 CVE-2023-40090: In BTM_BleVerifySignature of btm_ble
In BTM_BleVerifySignature of btm_ble.cc, there is a possible way to bypass signature validation due to side channel information disclosure. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-45776UNKNOWN≥ 14-next:0, < 14-next:2023-12-01≥ 14:0, < 14:2023-12-012023-12-01
CVE-2023-45776 CVE-2023-45776: In CreateAudioBroadcast of broadcaster
In CreateAudioBroadcast of broadcaster.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-40087UNKNOWN≥ 14-next:0, < 14-next:2023-12-01≥ 13:0, < 13:2023-12-01+1 more2023-12-01
CVE-2023-40087 CVE-2023-40087: In transcodeQ*ToFloat of btif_avrcp_audio_track
In transcodeQ*ToFloat of btif_avrcp_audio_track.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-40083UNKNOWN≥ 14-next:0, < 14-next:2023-12-01≥ 13:0, < 13:2023-12-01+1 more2023-12-01
CVE-2023-40083 CVE-2023-40083: In parse_gap_data of utils
In parse_gap_data of utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-45775UNKNOWN≥ 14-next:0, < 14-next:2023-12-01≥ 14:0, < 14:2023-12-012023-12-01
CVE-2023-45775 CVE-2023-45775: In CreateAudioBroadcast of broadcaster
In CreateAudioBroadcast of broadcaster.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-45773UNKNOWN≥ 14-next:0, < 14-next:2023-12-01≥ 13:0, < 13:2023-12-01+1 more2023-12-01
CVE-2023-45773 CVE-2023-45773: In multiple functions of btm_ble_gap
In multiple functions of btm_ble_gap.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-40080UNKNOWN≥ 14-next:0, < 14-next:2023-12-01≥ 13:0, < 13:2023-12-01+1 more2023-12-01
CVE-2023-40080 CVE-2023-40080: In multiple functions of btm_ble_gap
In multiple functions of btm_ble_gap.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-40088UNKNOWN≥ 14-next:0, < 14-next:2023-12-01≥ 13:0, < 13:2023-12-01+1 more2023-12-01
CVE-2023-40088 CVE-2023-40088: In callback_thread_event of com_android_bluetooth_btservice_AdapterService
In callback_thread_event of com_android_bluetooth_btservice_AdapterService.cpp, there is a possible memory corruption due to a use after free. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-40129UNKNOWN≥ 13:0, < 13:2023-10-012023-10-01
CVE-2023-40129 CVE-2023-40129: In build_read_multi_rsp of gatt_sr
In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-35666UNKNOWN≥ 13-next:0, < 13-next:2023-09-01≥ 13:0, < 13:2023-09-012023-09-01
CVE-2023-35666 CVE-2023-35666: In bta_av_rc_msg of bta_av_act
In bta_av_rc_msg of bta_av_act.cc, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-35684UNKNOWN≥ 13-next:0, < 13-next:2023-09-01≥ 13:0, < 13:2023-09-012023-09-01
CVE-2023-35684 CVE-2023-35684: In avdt_msg_asmbl of avdt_msg
In avdt_msg_asmbl of avdt_msg.cc, there is a possible out of bounds write due to an integer overflow. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-35673UNKNOWN≥ 13-next:0, < 13-next:2023-09-01≥ 13:0, < 13:2023-09-012023-09-01
CVE-2023-35673 CVE-2023-35673: In build_read_multi_rsp of gatt_sr
In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-35681UNKNOWN≥ 13-next:0, < 13-next:2023-09-01≥ 13:0, < 13:2023-09-012023-09-01
CVE-2023-35681 CVE-2023-35681: In eatt_l2cap_reconfig_completed of eatt_impl
In eatt_l2cap_reconfig_completed of eatt_impl.h, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-35658UNKNOWN≥ 13-next:0, < 13-next:2023-09-01≥ 13:0, < 13:2023-09-012023-09-01
CVE-2023-35658 CVE-2023-35658: In gatt_process_prep_write_rsp of gatt_cl
In gatt_process_prep_write_rsp of gatt_cl.cc, there is a possible privilege escalation due to a use after free. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
osv