CVE-2004-0775
Summary
| CVE | CVE-2004-0775 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-10-20 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Buffer overflow in WIDCOMM Bluetooth Connectivity Software, as used in products such as BTStackServer 1.3.2.7 and 1.4.2.10, Windows XP and Windows 98 with MSI Bluetooth Dongles, and HP IPAQ 5450 running WinCE 3.0, allows remote attackers to execute arbitrary code via certain service requests. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Widcomm | Bluetooth Communication Software | 1.4.1.03 | All | All | All |
| Application | Widcomm | Btstackserver | 1.3.2.7 | All | All | All |
| Application | Widcomm | Btstackserver | 1.4.2.10 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Pentest Limited - Specialists in security and Oracle | af854a3a-2127-422b-91ae-364da2661108 | www.pentest.co.uk | Patch, Vendor Advisory |
| 'ptl-2004-03: WIDCOMM Bluetooth Connectivity Software Buffer Overflows' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Neohapsis Archives - VulnWatch - #0029 - [VulnWatch] ptl-2004-03: WIDCOMM Bluetooth Connectivity Software Buffer Overflows | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| WIDCOMM Bluetooth a Virus Risk - InternetNews. | af854a3a-2127-422b-91ae-364da2661108 | www.internetnews.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.