cbcvebase.

Platform Packages Modules Bluetooth vulnerabilities

119 known vulnerabilities affecting platform/packages_modules_bluetooth.

Total CVEs
119
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
UNKNOWN119

Vulnerabilities

Page 5 of 6
CVE-2024-43763P4UNKNOWN≥ 15-next:0, < 15-next:2025-01-01≥ 15:0, < 15:2025-01-01+2 more2025-01-01
CVE-2024-43763 CVE-2024-43763: In build_read_multi_rsp of gatt_sr In build_read_multi_rsp of gatt_sr.cc, there is a possible denial of service due to a logic error in the code. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-49728P4UNKNOWN≥ 15-next:0, < 15-next:2025-04-01≥ 15:0, < 15:2025-04-01+2 more2025-04-01
CVE-2024-49728 CVE-2024-49728: In generateFileInfo of BluetoothOppSendFileInfo In generateFileInfo of BluetoothOppSendFileInfo.java, there is a possible cross user media disclosure due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-26453P4UNKNOWN≥ 16-next:0, < 16-next:2025-06-01≥ 15:0, < 15:2025-06-01+2 more2025-06-01
CVE-2025-26453 CVE-2025-26453: In isContentUriForOtherUser of BluetoothOppSendFileInfo In isContentUriForOtherUser of BluetoothOppSendFileInfo.java, there is a possible cross user data leak due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-40083P4UNKNOWN≥ 14-next:0, < 14-next:2023-12-01≥ 13:0, < 13:2023-12-01+1 more2023-12-01
CVE-2023-40083 CVE-2023-40083: In parse_gap_data of utils In parse_gap_data of utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-45781P4UNKNOWN≥ 14-next:0, < 14-next:2023-12-01≥ 13:0, < 13:2023-12-01+1 more2023-12-01
CVE-2023-45781 CVE-2023-45781: In parse_gap_data of utils In parse_gap_data of utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21198P4UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-21198 CVE-2023-21198: In remove_sdp_record of btif_sdp_server In remove_sdp_record of btif_sdp_server.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21200P4UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-21200 CVE-2023-21200: In on_remove_iso_data_path of btm_iso_impl In on_remove_iso_data_path of btm_iso_impl.h, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20980P4UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-20980 CVE-2023-20980: In btu_ble_ll_conn_param_upd_evt of btu_hcif In btu_ble_ll_conn_param_upd_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20952P4UNKNOWN≥ 13-next:0, < 13-next:2023-03-01≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-20952 CVE-2023-20952: In A2DP_BuildCodecHeaderSbc of a2dp_sbc In A2DP_BuildCodecHeaderSbc of a2dp_sbc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21080P4UNKNOWN≥ 13-next:0, < 13-next:2023-04-01≥ 13:0, < 13:2023-04-012023-04-01
CVE-2023-21080 CVE-2023-21080: In register_notification_rsp of btif_rc In register_notification_rsp of btif_rc.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20974P4UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-20974 CVE-2023-20974: In btm_ble_add_resolving_list_entry_complete of btm_ble_privacy In btm_ble_add_resolving_list_entry_complete of btm_ble_privacy.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20973P4UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-20973 CVE-2023-20973: In btm_create_conn_cancel_complete of btm_sec In btm_create_conn_cancel_complete of btm_sec.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20972P4UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-20972 CVE-2023-20972: In btm_vendor_specific_evt of btm_devctl In btm_vendor_specific_evt of btm_devctl.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20979P4UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-20979 CVE-2023-20979: In GetNextSourceDataPacket of bta_av_co In GetNextSourceDataPacket of bta_av_co.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20552P4UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20552 CVE-2022-20552: In btif_a2dp_sink_command_ready of btif_a2dp_sink In btif_a2dp_sink_command_ready of btif_a2dp_sink.cc, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20467P4UNKNOWN≥ 13-next:0, < 13-next:2023-03-01≥ 13:0, < 13:2023-03-012023-03-01
CVE-2022-20467 CVE-2022-20467: In isBluetoothShareUri of BluetoothOppUtility In isBluetoothShareUri of BluetoothOppUtility.java, there is a possible incorrect file read due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2023-21190P4UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-21190 CVE-2023-21190: In btm_acl_encrypt_change of btm_acl In btm_acl_encrypt_change of btm_acl.cc, there is a possible way for a remote device to turn off encryption without resulting in a terminated connection due to an unusual root cause. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2022-20521P4UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20521 CVE-2022-20521: In sdpu_find_most_specific_service_uuid of sdp_utils In sdpu_find_most_specific_service_uuid of sdp_utils.cc, there is a possible way to crash Bluetooth due to a missing null check. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2023-20992P4UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-20992 CVE-2023-20992: In on_iso_link_quality_read of btm_iso_impl In on_iso_link_quality_read of btm_iso_impl.h, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20988P4UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-20988 CVE-2023-20988: In btm_read_rssi_complete of btm_acl In btm_read_rssi_complete of btm_acl.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth server with System execution privileges needed. User interaction is not needed for exploitation.
osv
Platform Packages Modules Bluetooth vulnerabilities | cvebase