Platform System Bt vulnerabilities
66 known vulnerabilities affecting platform/system_bt.
Total CVEs
66
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN66
Vulnerabilities
Page 1 of 4
CVE-2022-20140P2UNKNOWN≥ 12:0, < 12:2022-06-01≥ 12L:0, < 12L:2022-06-012022-06-01
CVE-2022-20140 CVE-2022-20140: In read_multi_rsp of gatt_sr
In read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0316P2UNKNOWN≥ 8.0:0, < 8.0:2021-01-01≥ 8.1:0, < 8.1:2021-01-01+3 more2021-01-01
CVE-2021-0316 CVE-2021-0316: In avrc_pars_vendor_cmd of avrc_pars_tg
In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20229P2UNKNOWN≥ 10:0, < 10:2022-07-01≥ 11:0, < 11:2022-07-01+1 more2022-07-01
CVE-2022-20229 CVE-2022-20229: In bta_hf_client_handle_cind_list_item of bta_hf_client_at
In bta_hf_client_handle_cind_list_item of bta_hf_client_at.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-49748P2UNKNOWN≥ 12:0, < 12:2025-01-01≥ 12L:0, < 12L:2025-01-012025-01-01
CVE-2024-49748 CVE-2024-49748: In gatts_process_primary_service_req of gatt_sr
In gatts_process_primary_service_req of gatt_sr.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21250P2UNKNOWN≥ 11:0, < 11:2023-07-01≥ 12:0, < 12:2023-07-01+1 more2023-07-01
CVE-2023-21250 CVE-2023-21250: In gatt_end_operation of gatt_utils
In gatt_end_operation of gatt_utils.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0397P2UNKNOWN≥ 8.1:0, < 8.1:2021-03-01≥ 9:0, < 9:2021-03-01+2 more2021-03-01
CVE-2021-0397 CVE-2021-0397: In sdp_copy_raw_data of sdp_discovery
In sdp_copy_raw_data of sdp_discovery.cc, there is a possible system compromise due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0474P3UNKNOWN≥ 8.1:0, < 8.1:2021-05-01≥ 9:0, < 9:2021-05-01+2 more2021-05-01
CVE-2021-0474 CVE-2021-0474: In avrc_msg_cback of avrc_api
In avrc_msg_cback of avrc_api.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0225P2UNKNOWN≥ 10:0, < 10:2020-07-012020-07-01
CVE-2020-0225 CVE-2020-0225: In a2dp_vendor_ldac_decoder_decode_packet of a2dp_vendor_ldac_decoder
In a2dp_vendor_ldac_decoder_decode_packet of a2dp_vendor_ldac_decoder.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-49747P2UNKNOWN≥ 12:0, < 12:2025-01-01≥ 12L:0, < 12L:2025-01-012025-01-01
CVE-2024-49747 CVE-2024-49747: In gatts_process_read_by_type_req of gatt_sr
In gatts_process_read_by_type_req of gatt_sr.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0380P2UNKNOWN≥ 8.0:0, < 8.0:2020-09-01≥ 8.1:0, < 8.1:2020-09-01+2 more2020-09-01
CVE-2020-0380 CVE-2020-0380: In allocExcessBits of bitalloc
In allocExcessBits of bitalloc.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0471P3UNKNOWN≥ 8.0:0, < 8.0:2021-01-01≥ 8.1:0, < 8.1:2021-01-01+3 more2021-01-01
CVE-2020-0471 CVE-2020-0471: In reassemble_and_dispatch of packet_fragmenter
In reassemble_and_dispatch of packet_fragmenter.cc, there is a possible way to inject packets into an encrypted Bluetooth connection due to improper input validation. This could lead to remote escalation of privilege between two Bluetooth devices by a proximal attacker, with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20222P3UNKNOWN≥ 12:0, < 12:2022-07-01≥ 12L:0, < 12L:2022-07-012022-07-01
CVE-2022-20222 CVE-2022-20222: In read_attr_value of gatt_db
In read_attr_value of gatt_db.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20951P3UNKNOWN≥ 11:0, < 11:2023-03-01≥ 12:0, < 12:2023-03-01+1 more2023-03-01
CVE-2023-20951 CVE-2023-20951: In gatt_process_prep_write_rsp of gatt_cl
In gatt_process_prep_write_rsp of gatt_cl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20411P3UNKNOWN≥ 10:0, < 10:2022-12-01≥ 11:0, < 11:2022-12-01+1 more2022-12-01
CVE-2022-20411 CVE-2022-20411: In avdt_msg_asmbl of avdt_msg
In avdt_msg_asmbl of avdt_msg.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20954P3UNKNOWN≥ 11:0, < 11:2023-03-01≥ 12:0, < 12:2023-03-01+1 more2023-03-01
CVE-2023-20954 CVE-2023-20954: In SDP_AddAttribute of sdp_db
In SDP_AddAttribute of sdp_db.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39708P3UNKNOWN≥ 12:0, < 12:2022-03-01≥ 12L:0, < 12L:2022-03-012022-03-01
CVE-2021-39708 CVE-2021-39708: In gatt_process_notification of gatt_cl
In gatt_process_notification of gatt_cl.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20361P3UNKNOWN≥ 10:0, < 10:2022-08-01≥ 11:0, < 11:2022-08-01+1 more2022-08-01
CVE-2022-20361 CVE-2022-20361: In btif_dm_auth_cmpl_evt of btif_dm
In btif_dm_auth_cmpl_evt of btif_dm.cc, there is a possible vulnerability in Cross-Transport Key Derivation due to Weakness in Bluetooth Standard. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-34722P3UNKNOWN≥ 12:0, < 12:2025-01-01≥ 12L:0, < 12L:2025-01-012025-01-01
CVE-2024-34722 CVE-2024-34722: In smp_proc_rand of smp_act
In smp_proc_rand of smp_act.cc, there is a possible authentication bypass during legacy BLE pairing due to incorrect implementation of a protocol. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-43770P3UNKNOWN≥ 12:0, < 12:2025-01-01≥ 12L:0, < 12L:2025-01-012025-01-01
CVE-2024-43770 CVE-2024-43770: In gatts_process_find_info of gatt_sr
In gatts_process_find_info of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-43771P3UNKNOWN≥ 12:0, < 12:2025-01-01≥ 12L:0, < 12L:2025-01-012025-01-01
CVE-2024-43771 CVE-2024-43771: In gatts_process_read_req of gatt_sr
In gatts_process_read_req of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
1 / 4Next →