VYPR

Vendor CVEs

Nokia

All CVEs

167 total · sorted by risk
  • CVE-2019-17405MedNov 25, 2019
    risk 0.40cvss 6.1epss 0.01

    Nokia IMPACT < 18A: has Reflected self XSS

  • CVE-2025-24819MedApr 7, 2026
    risk 0.37cvss 5.7epss 0.00

    Nokia MantaRay NM is vulnerable to a Relative Path Traversal vulnerability due to improper validation of input parameter on the file system in Software Manager application.

  • CVE-2023-38299MedApr 22, 2024
    risk 0.36cvss 5.5epss 0.00

    Various software builds for the AT&T Calypso, Nokia C100, Nokia C200, and BLU View 3 devices leak the device IMEI to a system property that can be accessed by any local app on the device without any permissions or special privileges. Google restricted third-party apps from…

  • CVE-2021-32289MedSep 20, 2021
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in heif through through v3.6.2. A NULL pointer dereference exists in the function convertByteStreamToRBSP() located in nalutil.cpp. It allows an attacker to cause Denial of Service.

  • CVE-2022-28867MedJul 24, 2023
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website section. A malicious user can edit or add the templateName parameter in order to include JavaScript code, which is then stored and executed by a victim's web browser. The most common…

  • CVE-2022-28865MedJul 24, 2023
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in Nokia NetAct 22 through the Site Configuration Tool website section. A malicious user can change a filename of an uploaded file to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism for…

  • CVE-2021-26596MedMar 25, 2021
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Nokia NetAct 18A. A malicious user can change a filename of an uploaded file to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism for delivering malicious content is to include it as a…

  • CVE-2019-17406MedNov 25, 2019
    risk 0.35cvss 5.3epss 0.01

    Nokia IMPACT < 18A has path traversal that may lead to RCE if chained with CVE-2019-1743

  • CVE-2025-65885MedDec 26, 2025
    risk 0.33cvss 5.1epss 0.00

    An issue was discovered in the Delight Custom Firmware (CFW) for Nokia Symbian Belle devices on Nokia 808 (Delight v1.8), Nokia N8 (Delight v6.7), Nokia E7 (Delight v1.3), Nokia C7 (Delight v6.7), Nokia 700 (Delight v1.2), Nokia 701 (Delight v1.1), Nokia 603 (Delight v1.0),…

  • CVE-2023-25188MedJun 16, 2023
    risk 0.33cvss 5.1epss 0.00

    An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) removes security hardenings from the Nokia Single RAN BTS baseband unit, the BTS baseband unit diagnostic tool AaShell (which is by default disabled) allows…

  • CVE-2023-25186MedJun 16, 2023
    risk 0.33cvss 5.1epss 0.00

    An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) removes security hardenings from a Nokia Single RAN BTS baseband unit, a directory path traversal in the Nokia BTS baseband unit diagnostic tool AaShell (which is…

  • CVE-2025-27026MedJul 2, 2025
    risk 0.32cvss 4.9epss 0.00

    A missing double-check feature in the WebGUI for CLI deactivation in Infinera G42 version R6.1.3 allows an authenticated administrator to make other management interfaces unavailable via local and network interfaces. The CLI deactivation via the WebGUI does not only stop CLI…

  • CVE-2022-30903MedJun 14, 2022
    risk 0.31cvss 4.8epss 0.01

    Nokia "G-2425G-A" Bharti Airtel Routers Hardware version "3FE48299DEAA" Software Version "3FE49362IJHK42" is vulnerable to Cross-Site Scripting (XSS) via the admin->Maintenance>Device Management.

  • CVE-2021-30003MedApr 2, 2021
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered on Nokia G-120W-F 3FE46606AGAB91 devices. There is Stored XSS in the administrative interface via urlfilter.cgi?add url_address.

  • CVE-2022-38788MedSep 15, 2022
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Nokia FastMile 5G Receiver 5G14-B 1.2104.00.0281. Bluetooth on the Nokia ODU uses outdated pairing mechanisms, allowing an attacker to passively intercept a paring handshake and (after offline cracking) retrieve the PIN and LTK (long-term key).

  • CVE-2019-17404MedNov 25, 2019
    risk 0.28cvss 4.3epss 0.01

    Nokia IMPACT < 18A: allows full path disclosure

  • CVE-2021-35483MedMar 3, 2026
    risk 0.27cvss 4.1epss 0.00

    The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload JavaScript files via the /ui/rest-proxy/application fileupload parameter. This can occur during the adding of a new application, or during…

  • CVE-2025-24328MedJul 2, 2025
    risk 0.27cvss 4.2epss 0.00

    Sending a crafted SOAP "set" operation message within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network can cause Nokia Single RAN baseband OAM service component restart with software versions earlier than release 24R1-SR 1.0 MP. This issue…

  • CVE-2023-41354MedNov 3, 2023
    risk 0.26cvss 4.0epss 0.00

    Chunghwa Telecom NOKIA G-040W-Q Firewall function does not block ICMP TIMESTAMP requests by default, an unauthenticated remote attacker can exploit this vulnerability by sending a crafted package, resulting in partially sensitive information exposed to an actor.

  • CVE-2023-25185LowJun 16, 2023
    risk 0.25cvss 3.8epss 0.00

    An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. A mobile network solution internal fault was found in Nokia Single RAN software releases. Certain software processes in the BTS internal software design have unnecessarily high privileges to BTS…

  • CVE-2025-24334LowJul 2, 2025
    risk 0.21cvss 3.3epss 0.00

    The Nokia Single RAN baseband software earlier than 23R2-SR 1.0 MP can be made to reveal the exact software release version by sending a specific HTTP POST request through the Mobile Network Operator (MNO) internal RAN management network.

  • CVE-2023-6728LowOct 17, 2024
    risk 0.21cvss 3.3epss 0.00

    Nokia SR OS bof.cfg file encryption is vulnerable to a brute force attack. This weakness allows an attacker in possession of the encrypted file to decrypt the bof.cfg file and obtain the BOF configuration content.

  • CVE-2024-28811LowSep 30, 2024
    risk 0.21cvss 3.3epss 0.00

    An issue was discovered in Infinera hiT 7300 5.60.50. A web application allows a remote privileged attacker to execute applications contained in a specific OS directory via HTTP invocations.

  • CVE-2023-25189LowSep 25, 2024
    risk 0.21cvss 3.3epss 0.00

    BTS is affected by information disclosure vulnerability where mobile network operator personnel connected over BTS Web Element Manager, regardless of the access privileges, having a possibility to read BTS service operation details performed by Nokia Care service personnel via…

  • CVE-2024-28808LowSep 30, 2024
    risk 0.18cvss 2.7epss 0.00

    An issue was discovered in Infinera hiT 7300 5.60.50. Hidden functionality in the web interface allows a remote authenticated attacker to access reserved information by accessing undocumented web applications.

  • CVE-2023-31044LowMar 3, 2026
    risk 0.13cvss 2.0epss 0.00

    An issue was discovered in Nokia Impact before Mobile 23_FP1. In Impact DM 19.11 onwards, a remote authenticated user, using the Add Campaign functionality, can inject a malicious payload within the Campaign Name. This data can be exported to a CSV file. Attackers can populate…

  • CVE-2025-24335LowJul 2, 2025
    risk 0.13cvss 2.0epss 0.00

    Nokia Single RAN baseband software versions earlier than 24R1-SR 2.1 MP contain a SOAP message input validation flaw, which in theory could potentially be used for causing resource exhaustion in the Single RAN baseband OAM service. No practical exploit has been detected for…

  • CVE-2009-0649Feb 20, 2009
    risk 0.04cvss epss 0.08

    The web browser in Symbian OS on the Nokia N95 cell phone allows remote attackers to cause a denial of service (crash) via JavaScript code that calls the setAttributeNode method.

  • CVE-2005-2277Jul 15, 2005
    risk 0.04cvss epss 0.13

    Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename argument of a PUT command.

  • CVE-2005-2250Jul 13, 2005
    risk 0.04cvss epss 0.10

    Buffer overflow in Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary code via a long filename in an OBEX file share.

  • CVE-2012-2442Jul 25, 2012
    risk 0.03cvss epss 0.03

    Buffer overflow in the Video Manager in Nokia PC Suite 7.1.180.64 and earlier allows remote attackers to cause a denial of service via a crafted mp4 file.

  • CVE-2011-0498Jan 20, 2011
    risk 0.03cvss epss 0.06

    Stack-based buffer overflow in Nokia Multimedia Player 1.00.55.5010, and possibly other versions, allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long entry in a playlist (.npl) file.

  • CVE-2009-0734Feb 25, 2009
    risk 0.03cvss epss 0.05

    Heap-based buffer overflow in MultimediaPlayer.exe 6.86.240.7 in Nokia PC Suite 6.86.9.3 allows remote attackers to execute arbitrary code via a long string in a .m3u playlist file.

  • CVE-2008-4135Sep 19, 2008
    risk 0.03cvss epss 0.04

    Symbian OS S60 3rd edition on the Nokia E90 Communicator 07.40.1.2 Ra-6 and Nseries N82 allows remote attackers to cause a denial of service (device crash) via multiple deauthentication (DeAuth) frames.

  • CVE-2006-4464Aug 31, 2006
    risk 0.03cvss epss 0.03

    The Nokia Browser, possibly Nokia Symbian 60 Browser 3rd edition, allows remote attackers to cause a denial of service (crash) via JavaScript that constructs a large Unicode string.

  • CVE-2006-0797Feb 19, 2006
    risk 0.03cvss epss 0.05

    Nokia N70 cell phone allows remote attackers to cause a denial of service (reboot or shutdown) through a wireless Bluetooth connection via a malformed Logical Link Control and Adaptation Protocol (L2CAP) packet whose length field is less than the actual length of the packet,…

  • CVE-2005-1294Apr 24, 2005
    risk 0.03cvss epss 0.01

    The affix_sock_register in the Affix Bluetooth Protocol Stack for Linux might allow local users to gain privileges via a socket call with a negative protocol value, which is used as an array index.

  • CVE-2005-0681Mar 6, 2005
    risk 0.03cvss epss 0.03

    Nokia Symbian 60 allows remote attackers to cause a denial of service (phone restart) via a Bluetooth nickname.

  • CVE-2003-0802Oct 6, 2003
    risk 0.03cvss epss 0.07

    Nokia Electronic Documentation (NED) 5.0 allows remote attackers to obtain a directory listing of the WebLogic web root, and the physical path of the NED server, via a "retrieve" action with a location parameter of . (dot).

  • CVE-2003-0801Oct 6, 2003
    risk 0.03cvss epss 0.12

    Cross-site scripting (XSS) vulnerability in Nokia Electronic Documentation (NED) 5.0 allows remote attackers to execute arbitrary web script and steal cookies via a URL to the docs/ directory that contains the script.

  • CVE-2003-0803Oct 6, 2003
    risk 0.03cvss epss 0.06

    Nokia Electronic Documentation (NED) 5.0 allows remote attackers to use NED as an open HTTP proxy via a URL in the location parameter, which NED accesses and returns to the user.

  • CVE-2025-7406HigJun 30, 2026
    risk 0.00cvss 7.8epss 0.00

    Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privileges can escalate to full root privileges on the host. Successful exploitation results in root-level access to the filesystem and the…

  • CVE-2025-24816MedJun 30, 2026
    risk 0.00cvss 6.5epss 0.00

    Nokia MantaRay is subject to an Improper Access Control vulnerability due to insufficient authorization within the API. Successful exploitation could allow an authenticated attacker to retrieve confidential information beyond their assigned privileges.

  • CVE-2025-24815HigJun 30, 2026
    risk 0.00cvss 7.8epss 0.00

    Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due to insufficient file type validation. Successful exploitation could allow an authenticated attacker to upload malicious files onto the system.

  • CVE-2015-6929Sep 16, 2015
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Nokia Networks (formerly Nokia Solutions and Networks and Nokia Siemens Networks) @vantage Commander allow remote attackers to inject arbitrary web script or HTML via the (1) idFilter or (2) nameFilter parameter to…

  • CVE-2011-1472Mar 29, 2011
    risk 0.00cvss epss 0.00

    The Nokia E75 phone with firmware before 211.12.01 allows physically proximate attackers to bypass the Device Lock code by entering an unspecified button sequence at boot time.

  • CVE-2010-3374Oct 4, 2010
    risk 0.00cvss epss 0.00

    Qt Creator before 2.0.1 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

  • CVE-2009-4975Aug 2, 2010
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in webview.cpp in QtDemoBrowser allows remote attackers to inject arbitrary web script or HTML via a URL associated with a nonexistent domain name, related to a "universal XSS" issue, a similar vulnerability to CVE-2010-2536.

  • CVE-2009-2538Jul 20, 2009
    risk 0.00cvss epss 0.03

    The Nokia N95 running Symbian OS 9.2, N82, and N810 Internet Tablet allow remote attackers to cause a denial of service (memory consumption) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.

  • CVE-2008-5827Jan 2, 2009
    risk 0.00cvss epss 0.03

    The Nokia 6131 Near Field Communication (NFC) phone with 05.12 firmware automatically installs software upon completing the download of a JAR file, which makes it easier for remote attackers to execute arbitrary code via a crafted URI record in an NDEF tag.