← Back

Bluez Project

bluez_project

4 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Bluez
bluez
Hcidump
hcidump

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Bluez Project
1Bluez
May 6, 2026
Dec 8, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In BlueZ 5.42, an out-of-bounds read was identified in "packet_hexdump" function in "monitor/packet.c" source file. This issue can be triggered by processing a corrupted dump file and will result in btmon crash.
1Bluez Project
1Bluez
Apr 23, 2026
Dec 31, 2006
N/A· v4
N/A· v3
5.4 MEDIUM· v2
hidd in BlueZ (bluez-utils) before 2.25 allows remote attackers to obtain control of the (1) Mouse and (2) Keyboard Human Interface Device (HID) via a certain configuration of two HID (PSM) endpoints, operating as a serv...Show more
hidd in BlueZ (bluez-utils) before 2.25 allows remote attackers to obtain control of the (1) Mouse and (2) Keyboard Human Interface Device (HID) via a certain configuration of two HID (PSM) endpoints, operating as a server, aka HidAttack.Show less
1Bluez Project
1Hcidump
Apr 16, 2026
Feb 13, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in l2cap.c in hcidump 1.29 allows remote attackers to cause a denial of service (crash) through a wireless Bluetooth connection via a malformed Logical Link Control and Adaptation Protocol (L2CAP) packet.
1Bluez Project
1Bluez
Apr 16, 2026
Aug 12, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
security.c in hcid for BlueZ 2.16, 2.17, and 2.18 allows remote attackers to execute arbitrary commands via shell metacharacters in the Bluetooth device name when invoking the PIN helper.