Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
All versions of the package node-bluetooth-serial-port are vulnerable to Buffer Overflow via the findSerialPortChannel method due to improper user input length validation.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
未进行输入大小检查的缓冲区拷贝(传统缓冲区溢出)
Vulnerability Title
npm node-bluetooth 安全漏洞
Vulnerability Description
npm node-bluetooth是美国npm公司的一个 Node.js 的蓝牙串口通信。 npm node-bluetooth 存在安全漏洞,该漏洞源于不正确的用户输入长度验证,攻击者利用该漏洞可以通过 findSerialPortChannel 方法导致缓冲区溢出。
CVSS Information
N/A
Vulnerability Type
N/A