Nokia
nokia
146 CVEs • 110 products
Products (110)
Click to collapseToggle
Products (110)
Click to collapse
CVEs (146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Nokia 11350 Optical Management System Jun 17, 2026 Sep 13, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 In NOKIA 1350 OMS R14.2, an Insertion of Sensitive Information into an Application Log File vulnerability occurs. The web application stores critical information, such as cleartext user credentials, in world-readable fil...Show more |
1Nokia 11350 Optical Management System Jun 17, 2026 Sep 13, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This allows authenticated users to execute commands on the operating system. |
1Nokia 11350 Optical Management System Jun 17, 2026 Sep 13, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 In NOKIA 1350 OMS R14.2, multiple SQL Injection vulnerabilities occurs. Exploitation requires an authenticated attacker. Through the injection of arbitrary SQL statements, a potential authenticated attacker can modify qu...Show more |
1Nokia 11350 Optical Management System Jun 17, 2026 Sep 13, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 In NOKIA 1350 OMS R14.2, Insufficiently Protected Credentials (cleartext administrator password) occur in the edit configuration page. Exploitation requires an authenticated attacker. |
1Nokia 11350 Optical Management System Jun 17, 2026 Sep 13, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This vulnerability allow unauthenticated users to execute commands on the operating system. |
1Nokia 11350 Optical Management System Jun 17, 2026 Sep 13, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 In NOKIA 1350 OMS R14.2, an Open Redirect vulnerability occurs is the login page via next HTTP GET parameter. |
NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'. |
Nokia "G-2425G-A" Bharti Airtel Routers Hardware version "3FE48299DEAA" Software Version "3FE49362IJHK42" is vulnerable to Cross-Site Scripting (XSS) via the admin->Maintenance>Device Management. |
1Nokia 1Broadcast Message Center Jun 17, 2026 May 25, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Nokia Broadcast Message Center through 11.1.0 allows an authenticated user to perform a Boolean Blind SQL Injection attack on the endpoint /owui/block/send-receive-updates (for the Manage Alerts page) via the extIdentifi...Show more |
Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass. A malicious unauthenticated user can get access to all the functionalities exposed via the web panel, circumventing the authentication p...Show more |
Nokia FastMile 3TG00118ABAD52 devices allow privilege escalation by an authenticated user via is_ctc_admin=1 to login_web_app.cgi and use of Import Config File. |
An issue was discovered in heif through through v3.6.2. A NULL pointer dereference exists in the function convertByteStreamToRBSP() located in nalutil.cpp. It allows an attacker to cause Denial of Service. |
An issue was discovered in heif through v3.6.2. A global-buffer-overflow exists in the function HevcDecoderConfigurationRecord::getPicHeight() located in hevcdecoderconfigrecord.cpp. It allows an attacker to cause code E...Show more |
An issue was discovered in heif through v3.6.2. A global-buffer-overflow exists in the function HevcDecoderConfigurationRecord::getPicWidth() located in hevcdecoderconfigrecord.cpp. It allows an attacker to cause code Ex...Show more |
An issue was discovered on Nokia G-120W-F 3FE46606AGAB91 devices. There is Stored XSS in the administrative interface via urlfilter.cgi?add url_address. |
An issue was discovered in Nokia NetAct 18A. A remote user, authenticated to the NOKIA NetAct Web Page, can visit the Site Configuration Tool web site section and arbitrarily upload potentially dangerous files without re...Show more |
An issue was discovered in Nokia NetAct 18A. A malicious user can change a filename of an uploaded file to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism f...Show more |
1Nokia 31830 Photonic Service Switch 16 Firmware 1830 Photonic Service Switch 32 Firmware1830 Photonic Service Switch 4 FirmwareNov 21, 2024 Jan 31, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the management interface in Alcatel-Lucent 1830 Photonic Service Switch (PSS) 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the myurl param...Show more |
Nokia IMPACT < 18A has path traversal that may lead to RCE if chained with CVE-2019-1743 |
Nokia IMPACT < 18A: has Reflected self XSS |