CVE-2006-6908
Estado: ModificadaAlta (10)—
Buffer overflow in the Bluetooth Stack COM Server in the Widcomm Bluetooth stack, as packaged as Widcomm Stack 3.x and earlier on Windows, Widcomm BTStackServer 1.4.2.10 and 1.3.2.7 on Windows, Widcomm Bluetooth Communication Software 1.4.1.03 on Windows, and the Bluetooth implementation in Windows Mobile or Windows CE on the HP IPAQ 2215 and 5450, allows remote attackers to cause a denial of service (service crash) and possibly execute arbitrary code via unspecified vectors.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
- Puntuación base: 10
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 30%
- Percentil entre todas las CVEs puntuadas: 98
- Fecha de la puntuación: 3/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (3)
CWE
- NVD-CWE-Other
Referencias
- http://events.ccc.de/congress/2006-mediawiki//images/f/fb/23c3_Bluetooh_revisited.pdf
- http://osvdb.org/37587
- http://www.securityfocus.com/archive/1/455889/100/0/threaded
- http://events.ccc.de/congress/2006-mediawiki//images/f/fb/23c3_Bluetooh_revisited.pdf
- http://osvdb.org/37587
- http://www.securityfocus.com/archive/1/455889/100/0/threaded
JSON original (NVD)
Mostrar
{
"id": "CVE-2006-6908",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": true,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-12-31T05:00:00.000",
"references": [
{
"url": "http://events.ccc.de/congress/2006-mediawiki//images/f/fb/23c3_Bluetooh_revisited.pdf",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/37587",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/455889/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://events.ccc.de/congress/2006-mediawiki//images/f/fb/23c3_Bluetooh_revisited.pdf",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/37587",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/455889/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Buffer overflow in the Bluetooth Stack COM Server in the Widcomm Bluetooth stack, as packaged as Widcomm Stack 3.x and earlier on Windows, Widcomm BTStackServer 1.4.2.10 and 1.3.2.7 on Windows, Widcomm Bluetooth Communication Software 1.4.1.03 on Windows, and the Bluetooth implementation in Windows Mobile or Windows CE on the HP IPAQ 2215 and 5450, allows remote attackers to cause a denial of service (service crash) and possibly execute arbitrary code via unspecified vectors."
},
{
"lang": "es",
"value": "Desbordamiento de búfer en la el Servidor COM de Pila Bluetooth de la pila Bluetooth Widcomm, empaquetada en Pila Widcomm 3.x y anteriores en Windows, Widcomm BTStackServer 1.4.2.10 y 1.3.2.7 en Windows, Widcomm Bluetooth Communication Software 1.4.1.03 en Windows, y la implementación de Bluetooth en Windows Mobile o Windows CE en las HP IPAQ 2215 y 5450, permite a atacantes remotos provocar una denegación de servicio (caída del servicio) y posiblemente ejecutar código de su elección a través de vectores no especificados."
}
],
"lastModified": "2026-06-16T22:34:01.757",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:broadcom:widcomm_bluetooth:1.4.1.03:*:windows:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "21324BCD-F525-4DD8-8860-C6744F0A6EA7"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:broadcom:widcomm_bluetooth:*:*:windows:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "292A0E2F-5536-4C73-9B6C-02074F06A490",
"versionEndIncluding": "3"
},
{
"criteria": "cpe:2.3:o:broadcom:widcomm_bluetooth:1.3.2.7:*:windows:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4028E5BC-625E-448E-9C9D-98DB70E647CD"
},
{
"criteria": "cpe:2.3:o:broadcom:widcomm_bluetooth:1.4.2.10:*:windows:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A86B6AC9-D1C8-4D8B-B744-B041BD255089"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_embedded_compact:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5F4C5281-4CF0-4BCE-BF7D-391149F38E2F"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_mobile:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D553418E-61B6-4BCA-9260-693260A9BB86"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}