← Back

Nokia

nokia

146 CVEs • 110 products

Products (110)

Click to collapse
Toggle
Netact
netact
Impact
impact
Mantaray Nm
mantaray_nm
G42 Firmware
g42_firmware
Affix
affix
6131 Nfc
6131_nfc
Heif
heif
Wavesuite Noc
wavesuite_noc
N70
n70
Symbian
symbian
N95
n95
Impact Mobile
impact_mobile
6210 Handset
6210_handset
Sgsn Dx200
sgsn_dx200
Ipso
ipso
Ggsn
ggsn
6310i
Series
series
9500
3210
7610
Series 40
series_40
N82
n82
Nokia Pc Suite
nokia_pc_suite
Qtdemobrowser
qtdemobrowser
Qt Creator
qt_creator
E75 Firmware
e75_firmware
E75
e75
Pc Suite
pc_suite
Vitalsuite
vitalsuite
One Nds
one-nds
Infinera Dna
infinera_dna
S60
s60
8810 4g
8810_4g
G 120w F
g-120w-f
Fastmile
fastmile
G 2425g A
g-2425g-a
G 040w Q
g-040w-q
Hit 7300
hit_7300
808 Pureview
808_pureview
C7
c7
N8
n8

CVEs (146)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nokia
11350 Optical Management System
Jun 17, 2026
Sep 13, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
In NOKIA 1350 OMS R14.2, an Insertion of Sensitive Information into an Application Log File vulnerability occurs. The web application stores critical information, such as cleartext user credentials, in world-readable fil...Show more
In NOKIA 1350 OMS R14.2, an Insertion of Sensitive Information into an Application Log File vulnerability occurs. The web application stores critical information, such as cleartext user credentials, in world-readable files in the filesystem.Show less
1Nokia
11350 Optical Management System
Jun 17, 2026
Sep 13, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This allows authenticated users to execute commands on the operating system.
1Nokia
11350 Optical Management System
Jun 17, 2026
Sep 13, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
In NOKIA 1350 OMS R14.2, multiple SQL Injection vulnerabilities occurs. Exploitation requires an authenticated attacker. Through the injection of arbitrary SQL statements, a potential authenticated attacker can modify qu...Show more
In NOKIA 1350 OMS R14.2, multiple SQL Injection vulnerabilities occurs. Exploitation requires an authenticated attacker. Through the injection of arbitrary SQL statements, a potential authenticated attacker can modify query syntax and perform unauthorized (and unexpected) operations against the remote database.Show less
1Nokia
11350 Optical Management System
Jun 17, 2026
Sep 13, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In NOKIA 1350 OMS R14.2, Insufficiently Protected Credentials (cleartext administrator password) occur in the edit configuration page. Exploitation requires an authenticated attacker.
1Nokia
11350 Optical Management System
Jun 17, 2026
Sep 13, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This vulnerability allow unauthenticated users to execute commands on the operating system.
1Nokia
11350 Optical Management System
Jun 17, 2026
Sep 13, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In NOKIA 1350 OMS R14.2, an Open Redirect vulnerability occurs is the login page via next HTTP GET parameter.
1Nokia
1Vitalsuite
Jun 17, 2026
Jun 16, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'.
1Nokia
1G 2425g A Firmware
Jun 17, 2026
Jun 14, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Nokia "G-2425G-A" Bharti Airtel Routers Hardware version "3FE48299DEAA" Software Version "3FE49362IJHK42" is vulnerable to Cross-Site Scripting (XSS) via the admin->Maintenance>Device Management.
1Nokia
1Broadcast Message Center
Jun 17, 2026
May 25, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Nokia Broadcast Message Center through 11.1.0 allows an authenticated user to perform a Boolean Blind SQL Injection attack on the endpoint /owui/block/send-receive-updates (for the Manage Alerts page) via the extIdentifi...Show more
Nokia Broadcast Message Center through 11.1.0 allows an authenticated user to perform a Boolean Blind SQL Injection attack on the endpoint /owui/block/send-receive-updates (for the Manage Alerts page) via the extIdentifier HTTP POST parameter. This allows an attacker to obtain the database user, database name, and database version information, and potentially database data.Show less
1Nokia
1Bts Trs Web Console
Jun 17, 2026
Feb 11, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass. A malicious unauthenticated user can get access to all the functionalities exposed via the web panel, circumventing the authentication p...Show more
Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass. A malicious unauthenticated user can get access to all the functionalities exposed via the web panel, circumventing the authentication process, by using URL encoding for the . (dot) character.Show less
1Nokia
1Fastmile Firmware
Jun 17, 2026
Dec 27, 2021
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
Nokia FastMile 3TG00118ABAD52 devices allow privilege escalation by an authenticated user via is_ctc_admin=1 to login_web_app.cgi and use of Import Config File.
1Nokia
1Heif
Jun 17, 2026
Sep 20, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in heif through through v3.6.2. A NULL pointer dereference exists in the function convertByteStreamToRBSP() located in nalutil.cpp. It allows an attacker to cause Denial of Service.
1Nokia
1Heif
Jun 17, 2026
Sep 20, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in heif through v3.6.2. A global-buffer-overflow exists in the function HevcDecoderConfigurationRecord::getPicHeight() located in hevcdecoderconfigrecord.cpp. It allows an attacker to cause code E...Show more
An issue was discovered in heif through v3.6.2. A global-buffer-overflow exists in the function HevcDecoderConfigurationRecord::getPicHeight() located in hevcdecoderconfigrecord.cpp. It allows an attacker to cause code Execution.Show less
1Nokia
1Heif
Jun 17, 2026
Sep 20, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in heif through v3.6.2. A global-buffer-overflow exists in the function HevcDecoderConfigurationRecord::getPicWidth() located in hevcdecoderconfigrecord.cpp. It allows an attacker to cause code Ex...Show more
An issue was discovered in heif through v3.6.2. A global-buffer-overflow exists in the function HevcDecoderConfigurationRecord::getPicWidth() located in hevcdecoderconfigrecord.cpp. It allows an attacker to cause code Execution.Show less
1Nokia
1G 120w F Firmware
Jun 17, 2026
Apr 2, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered on Nokia G-120W-F 3FE46606AGAB91 devices. There is Stored XSS in the administrative interface via urlfilter.cgi?add url_address.
1Nokia
1Netact
Jun 17, 2026
Mar 25, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in Nokia NetAct 18A. A remote user, authenticated to the NOKIA NetAct Web Page, can visit the Site Configuration Tool web site section and arbitrarily upload potentially dangerous files without re...Show more
An issue was discovered in Nokia NetAct 18A. A remote user, authenticated to the NOKIA NetAct Web Page, can visit the Site Configuration Tool web site section and arbitrarily upload potentially dangerous files without restrictions via the /netact/sct dir parameter in conjunction with the operation=upload value.Show less
1Nokia
1Netact
Jun 17, 2026
Mar 25, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in Nokia NetAct 18A. A malicious user can change a filename of an uploaded file to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism f...Show more
An issue was discovered in Nokia NetAct 18A. A malicious user can change a filename of an uploaded file to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims. Here, the /netact/sct filename parameter is used.Show less
1Nokia
31830 Photonic Service Switch 16 Firmware
1830 Photonic Service Switch 32 Firmware1830 Photonic Service Switch 4 Firmware
Nov 21, 2024
Jan 31, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the management interface in Alcatel-Lucent 1830 Photonic Service Switch (PSS) 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the myurl param...Show more
Cross-site scripting (XSS) vulnerability in the management interface in Alcatel-Lucent 1830 Photonic Service Switch (PSS) 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the myurl parameter to menu/pop.html.Show less
1Nokia
1Impact
Jun 17, 2026
Nov 25, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Nokia IMPACT < 18A has path traversal that may lead to RCE if chained with CVE-2019-1743
1Nokia
1Impact
Jun 17, 2026
Nov 25, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Nokia IMPACT < 18A: has Reflected self XSS