← Back

Nokia

nokia

146 CVEs • 110 products

Products (110)

Click to collapse
Toggle
Netact
netact
Impact
impact
Mantaray Nm
mantaray_nm
G42 Firmware
g42_firmware
Affix
affix
6131 Nfc
6131_nfc
Heif
heif
Wavesuite Noc
wavesuite_noc
N70
n70
Symbian
symbian
N95
n95
Impact Mobile
impact_mobile
6210 Handset
6210_handset
Sgsn Dx200
sgsn_dx200
Ipso
ipso
Ggsn
ggsn
6310i
Series
series
9500
3210
7610
Series 40
series_40
N82
n82
Nokia Pc Suite
nokia_pc_suite
Qtdemobrowser
qtdemobrowser
Qt Creator
qt_creator
E75 Firmware
e75_firmware
E75
e75
Pc Suite
pc_suite
Vitalsuite
vitalsuite
One Nds
one-nds
Infinera Dna
infinera_dna
S60
s60
8810 4g
8810_4g
G 120w F
g-120w-f
Fastmile
fastmile
G 2425g A
g-2425g-a
G 040w Q
g-040w-q
Hit 7300
hit_7300
808 Pureview
808_pureview
C7
c7
N8
n8

CVEs (146)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nokia
16131 Nfc
Apr 23, 2026
Jan 2, 2009
N/A· v4
N/A· v3
2.6 LOW· v2
The SmartPoster implementation on the Nokia 6131 Near Field Communication (NFC) phone with 05.12 firmware does not properly display the URI record when the Title record contains a certain combination of space, CR (aka \r...Show more
The SmartPoster implementation on the Nokia 6131 Near Field Communication (NFC) phone with 05.12 firmware does not properly display the URI record when the Title record contains a certain combination of space, CR (aka \r), and . (dot) characters, which allows remote attackers to trick a user into loading an arbitrary URI via a crafted NDEF tag, as demonstrated by (1) an http: URI for a malicious web site, (2) a tel: URI for a premium-rate telephone number, and (3) an sms: URI that triggers purchase of a ringtone.Show less
1Nokia
1Series 40
Apr 23, 2026
Aug 8, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple unspecified vulnerabilities in Nokia Series 40 3rd edition FP1, and possibly later devices, allow remote attackers to execute arbitrary code via unknown vectors, probably related to MIDP privilege escalation and...Show more
Multiple unspecified vulnerabilities in Nokia Series 40 3rd edition FP1, and possibly later devices, allow remote attackers to execute arbitrary code via unknown vectors, probably related to MIDP privilege escalation and persistent MIDlets, aka "ISSUES 11-15." NOTE: as of 20080807, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a company led by a well-known researcher, it is being assigned a CVE identifier for tracking purposes.Show less
1Nokia
1N95
Apr 23, 2026
Dec 15, 2007
N/A· v4
N/A· v3
7.1 HIGH· v2
Nokia N95 cell phone with RM-159 12.0.013 firmware allows remote attackers to cause a denial of service (device inoperability) via a SIP INVITE message accompanied by an immediately subsequent SIP CANCEL message, followe...Show more
Nokia N95 cell phone with RM-159 12.0.013 firmware allows remote attackers to cause a denial of service (device inoperability) via a SIP INVITE message accompanied by an immediately subsequent SIP CANCEL message, followed by a second SIP INVITE message in a different session.Show less
1Nokia
3Groupwise Mobile Server
Intellisync Mobile SuiteIntellisync Wireless Email Express
Apr 23, 2026
May 11, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allo...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to de/pda/dev_logon.asp and (2) multiple unspecified vectors in (a) usrmgr/registerAccount.asp, (b) de/create_account.asp, and other files.Show less
1Nokia
3Groupwise Mobile Server
Intellisync Mobile SuiteIntellisync Wireless Email Express
Apr 23, 2026
May 11, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
usrmgr/userList.asp in Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allows remote attackers to modify us...Show more
usrmgr/userList.asp in Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allows remote attackers to modify user account details and cause a denial of service (account deactivation) via the userid parameter in an update action.Show less
1Nokia
3Groupwise Mobile Server
Intellisync Mobile SuiteIntellisync Wireless Email Express
Apr 23, 2026
May 11, 2007
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allows remote attackers to obtain user names and other sens...Show more
Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allows remote attackers to obtain user names and other sensitive information via a direct request to (1) usrmgr/userList.asp or (2) usrmgr/userStatusList.asp.Show less
1Nokia
1N70
Apr 23, 2026
Jan 26, 2007
N/A· v4
N/A· v3
3.3 LOW· v2
The Nokia N70 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, as demonstrated by ussp-push.
1Nokia
1Symbian
Apr 16, 2026
Aug 31, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Nokia Browser, possibly Nokia Symbian 60 Browser 3rd edition, allows remote attackers to cause a denial of service (crash) via JavaScript that constructs a large Unicode string.
1Nokia
1N70
Apr 16, 2026
Feb 19, 2006
N/A· v4
N/A· v3
7.8 HIGH· v2
Nokia N70 cell phone allows remote attackers to cause a denial of service (reboot or shutdown) through a wireless Bluetooth connection via a malformed Logical Link Control and Adaptation Protocol (L2CAP) packet whose len...Show more
Nokia N70 cell phone allows remote attackers to cause a denial of service (reboot or shutdown) through a wireless Bluetooth connection via a malformed Logical Link Control and Adaptation Protocol (L2CAP) packet whose length field is less than the actual length of the packet, possibly triggering a buffer overflow, as demonstrated using the Bluetooth Stack Smasher (BSS).Show less
1Nokia
23210
7610
Apr 16, 2026
Sep 28, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Nokia 7610 and 3210 phones allows attackers to cause a denial of service via certain characters in the filename of a Bluetooth OBEX transfer.
1Nokia
1Affix
Apr 16, 2026
Aug 29, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
The event_pin_code_request function in the btsrv daemon (btsrv.c) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in a Bluetooth device name.
1Nokia
1Affix
Apr 16, 2026
Jul 15, 2005
N/A· v4
N/A· v3
10.0 HIGH· v2
Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename argument of a PUT command.
1Nokia
1Affix
Apr 16, 2026
Jul 13, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary code via a long filename in an OBEX file share.
1Nokia
19500
Apr 16, 2026
May 26, 2005
N/A· v4
N/A· v3
2.6 LOW· v2
The vCard viewer in Nokia 9500 allows attackers to cause a denial of service (crash) via a vCard with a long Name field, which causes the crash when the user views it.
1Nokia
1Affix
Apr 16, 2026
Apr 24, 2005
N/A· v4
N/A· v3
7.2 HIGH· v2
The affix_sock_register in the Affix Bluetooth Protocol Stack for Linux might allow local users to gain privileges via a socket call with a negative protocol value, which is used as an array index.
1Nokia
1Series
Apr 16, 2026
Mar 6, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Nokia Symbian 60 allows remote attackers to cause a denial of service (phone restart) via a Bluetooth nickname.
1Nokia
16310i
Apr 16, 2026
Mar 3, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple vulnerabilities in Nokia 6310(i) Mobile phones allow remote attackers to cause a denial of service (reset) via malformed Bluetooth OBject EXchange (OBEX) messages, probably triggering buffer overflows.
1Nokia
1Ggsn
Apr 16, 2026
Feb 3, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Nokia Gateway GPRS support node (GGSN) allows remote attackers to cause a denial of service (kernel panic) via a malformed IP packet with a 0xFF TCP option.
1Nokia
1Ipso
Apr 16, 2026
Oct 29, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unknown vulnerability in Nokia IPSO 3.7, configured as IP Clusters, allows remote attackers to cause a denial of service via unknown attack vectors.
1Nokia
1Electronic Documentation
Apr 16, 2026
Oct 6, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
Nokia Electronic Documentation (NED) 5.0 allows remote attackers to use NED as an open HTTP proxy via a URL in the location parameter, which NED accesses and returns to the user.