cbcvebase.

Platform System Bt vulnerabilities

66 known vulnerabilities affecting platform/system_bt.

Total CVEs
66
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN66

Vulnerabilities

Page 2 of 4
CVE-2024-43096P3UNKNOWN≥ 12:0, < 12:2025-01-01≥ 12L:0, < 12L:2025-01-012025-01-01
CVE-2024-43096 CVE-2024-43096: In build_read_multi_rsp of gatt_sr In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0507P3UNKNOWN≥ 8.1:0, < 8.1:2021-06-01≥ 9:0, < 9:2021-06-01+2 more2021-06-01
CVE-2021-0507 CVE-2021-0507: In handle_rc_metamsg_cmd of btif_rc In handle_rc_metamsg_cmd of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-40129P3UNKNOWN≥ 12:0, < 12:2023-10-01≥ 12L:0, < 12L:2023-10-012023-10-01
CVE-2023-40129 CVE-2023-40129: In build_read_multi_rsp of gatt_sr In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0918P3UNKNOWN≥ 12:0, < 12:2021-11-012021-11-01
CVE-2021-0918 CVE-2021-0918: In gatt_process_notification of gatt_cl In gatt_process_notification of gatt_cl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20345P3UNKNOWN≥ 12:0, < 12:2022-08-01≥ 12L:0, < 12L:2022-08-012022-08-01
CVE-2022-20345 CVE-2022-20345: In l2cble_process_sig_cmd of l2c_ble In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21273P3UNKNOWN≥ 11:0, < 11:2023-08-01≥ 12:0, < 12:2023-08-01+1 more2023-08-01
CVE-2023-21273 CVE-2023-21273: In SDP_AddAttribute of sdp_db In SDP_AddAttribute of sdp_db.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0475P3UNKNOWN≥ 10:0, < 10:2021-05-01≥ 11:0, < 11:2021-05-012021-05-01
CVE-2021-0475 CVE-2021-0475: In on_l2cap_data_ind of btif_sock_l2cap In on_l2cap_data_ind of btif_sock_l2cap.cc, there is possible memory corruption due to a use after free. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0449P3UNKNOWN≥ 11-next:0, < 11-next:2020-11-01≥ 8.0:0, < 8.0:2020-11-01+4 more2020-11-01
CVE-2020-0449 CVE-2020-0449: In btm_sec_disconnected of btm_sec In btm_sec_disconnected of btm_sec.cc, there is a possible memory corruption due to a use after free. This could lead to remote code execution in the Bluetooth server with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2020-0377P3UNKNOWN≥ 8.0:0, < 8.0:2020-10-01≥ 8.1:0, < 8.1:2020-10-01+3 more2020-10-01
CVE-2020-0377 CVE-2020-0377: In gatt_process_read_by_type_rsp of gatt_cl In gatt_process_read_by_type_rsp of gatt_cl.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth server with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0431P3UNKNOWN≥ 8.1:0, < 8.1:2021-04-01≥ 9:0, < 9:2021-04-01+2 more2021-04-01
CVE-2021-0431 CVE-2021-0431: In avrc_msg_cback of avrc_api In avrc_msg_cback of avrc_api.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure to a paired device with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0968P3UNKNOWN≥ 9:0, < 9:2021-12-01≥ 10:0, < 10:2021-12-01+2 more2021-12-01
CVE-2021-0968 CVE-2021-0968: In osi_malloc and osi_calloc of allocator In osi_malloc and osi_calloc of allocator.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20469P3UNKNOWN≥ 10:0, < 10:2022-12-01≥ 11:0, < 11:2022-12-01+2 more2022-12-01
CVE-2022-20469 CVE-2022-20469: In avct_lcb_msg_asmbl of avct_lcb_act In avct_lcb_msg_asmbl of avct_lcb_act.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21125P3UNKNOWN≥ 12:0, < 12:2025-03-01≥ 12L:0, < 12L:2025-03-012025-03-01
CVE-2023-21125 CVE-2023-21125: In btif_hh_hsdata_rpt_copy_cb of bta_hh In btif_hh_hsdata_rpt_copy_cb of bta_hh.cc, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21115P3UNKNOWN≥ 11:0, < 11:2023-06-01≥ 12:0, < 12:2023-06-01+1 more2023-06-01
CVE-2023-21115 CVE-2023-21115: In btm_sec_encrypt_change of btm_sec In btm_sec_encrypt_change of btm_sec.cc, there is a possible way to downgrade the link key type due to improperly used crypto. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20224P3UNKNOWN≥ 10:0, < 10:2022-07-01≥ 11:0, < 11:2022-07-01+1 more2022-07-01
CVE-2022-20224 CVE-2022-20224: In AT_SKIP_REST of bta_hf_client_at In AT_SKIP_REST of bta_hf_client_at.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure in the Bluetooth stack with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0435P3UNKNOWN≥ 8.1:0, < 8.1:2021-04-01≥ 9:0, < 9:2021-04-01+2 more2021-04-01
CVE-2021-0435 CVE-2021-0435: In avrc_proc_vendor_command of avrc_api In avrc_proc_vendor_command of avrc_api.cc, there is a possible leak of heap data due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0413P3UNKNOWN≥ 8.0:0, < 8.0:2020-10-01≥ 8.1:0, < 8.1:2020-10-01+3 more2020-10-01
CVE-2020-0413 CVE-2020-0413: In gatt_process_read_by_type_rsp of gatt_cl In gatt_process_read_by_type_rsp of gatt_cl.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth server with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0463P3UNKNOWN≥ 8.0:0, < 8.0:2020-12-01≥ 8.1:0, < 8.1:2020-12-01+3 more2020-12-01
CVE-2020-0463 CVE-2020-0463: In sdp_server_handle_client_req of sdp_server In sdp_server_handle_client_req of sdp_server.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure from the bluetooth server with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0522P3UNKNOWN≥ 9:0, < 9:2021-06-01≥ 10:0, < 10:2021-06-01+1 more2021-06-01
CVE-2021-0522 CVE-2021-0522: In ConnectionHandler::SdpCb of connection_handler In ConnectionHandler::SdpCb of connection_handler.cc, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20410P3UNKNOWN≥ 10:0, < 10:2022-10-01≥ 11:0, < 11:2022-10-01+1 more2022-10-01
CVE-2022-20410 CVE-2022-20410: In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
Platform System Bt vulnerabilities | cvebase