Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-0204


A heap overflow vulnerability was found in bluez in versions prior to 5.63. An attacker with local network access could pass specially crafted files causing an application to halt or crash, leading to a denial of service.


Published

2022-03-10T17:44:55.230

Last Modified

2024-11-21T06:38:08.037

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

CVSSv2 Vector

AV:A/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

6.5

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-119
  • Type: Primary
    CWE-190

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application bluez bluez < 5.63 Yes
Operating System fedoraproject fedora 35 Yes
Operating System debian debian_linux 10.0 Yes

References