Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

168 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.0%—Nokia I-240w-q Gpon ONT Firmware5/3/201917/6/2026
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 contains multiple hard coded credentials for the Telnet and SSH interfaces.
ModificadaAlta (7.5)2.4%—Nokia I-240w-q Gpon ONT Firmware5/3/201917/6/2026
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 allows a remote, unauthenticated attacker to enable telnetd on the router via a crafted HTTP request.
ModificadaMedia (4.3)1.2%—Nokia @vantage Commander16/9/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Nokia Networks (formerly Nokia Solutions and Networks and Nokia Siemens Networks) @vantage Commander allow remote attackers to inject arbitrary web script or HTML via the (1) idFilter or (2) nameFilter parameter to cftraces/filter/fl_copy.jsp; the (3) flName…
ModificadaMedia (5.8)2.1%—Nokia Maps & Places Project Nokia Maps & Places1/7/201517/6/2026
Open redirect vulnerability in nokia-mapsplaces.php in the Nokia Maps & Places plugin 1.6.6 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the href parameter to page/place.html. NOTE: this was originally reported as a cross-site scripting (XSS)…
ModificadaMedia (6.6)2.2%—Microsoft Nokia Asha 501 SoftwareMicrosoft Nokia Asha 50122/9/201417/6/2026
Microsoft Asha OS on the Microsoft Mobile Nokia Asha 501 phone 14.0.4 allows physically proximate attackers to bypass the lock-screen protection mechanism, and read or modify contact information or dial arbitrary telephone numbers, by tapping the SOS Option and then tapping the Green Call Option.
ModificadaMedia (4.3)2.7%💥 ExploitNokia PC Suite25/7/201216/6/2026
Buffer overflow in the Video Manager in Nokia PC Suite 7.1.180.64 and earlier allows remote attackers to cause a denial of service via a crafted mp4 file.
ModificadaAlta (7.2)0.31%—Nokia E75 FirmwareNokia E7529/3/201116/6/2026
The Nokia E75 phone with firmware before 211.12.01 allows physically proximate attackers to bypass the Device Lock code by entering an unspecified button sequence at boot time.
ModificadaAlta (9.3)5.7%💥 ExploitNokia Multimedia Player20/1/201116/6/2026
Stack-based buffer overflow in Nokia Multimedia Player 1.00.55.5010, and possibly other versions, allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long entry in a playlist (.npl) file.
ModificadaMedia (6.9)0.35%—Nokia QT Creator4/10/201016/6/2026
Qt Creator before 2.0.1 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
ModificadaMedia (4.3)1.1%—Nokia Qtdemobrowser2/8/201016/6/2026
Cross-site scripting (XSS) vulnerability in webview.cpp in QtDemoBrowser allows remote attackers to inject arbitrary web script or HTML via a URL associated with a nonexistent domain name, related to a "universal XSS" issue, a similar vulnerability to CVE-2010-2536.
ModificadaAlta (7.1)2.8%—Nokia SymbianNokia N82Nokia N810 Internet Tablet20/7/200916/6/2026
The Nokia N95 running Symbian OS 9.2, N82, and N810 Internet Tablet allow remote attackers to cause a denial of service (memory consumption) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.
ModificadaAlta (9.3)5.1%💥 ExploitNokia PC Suite25/2/200916/6/2026
Heap-based buffer overflow in MultimediaPlayer.exe 6.86.240.7 in Nokia PC Suite 6.86.9.3 allows remote attackers to execute arbitrary code via a long string in a .m3u playlist file.
ModificadaAlta (7.8)8.3%💥 ExploitNokia N95Nokia Symbian S60 Browser20/2/200916/6/2026
The web browser in Symbian OS on the Nokia N95 cell phone allows remote attackers to cause a denial of service (crash) via JavaScript code that calls the setAttributeNode method.
ModificadaAlta (7.5)2.5%—Nokia 6131 NFC2/1/200916/6/2026
The Nokia 6131 Near Field Communication (NFC) phone with 05.12 firmware automatically installs software upon completing the download of a JAR file, which makes it easier for remote attackers to execute arbitrary code via a crafted URI record in an NDEF tag.
ModificadaAlta (7.8)2.4%—Nokia 6131 NFC2/1/200916/6/2026
The Nokia 6131 Near Field Communication (NFC) phone with 05.12 firmware allows remote attackers to cause a denial of service (device crash) via (1) a large value in the payload length field in an NDEF record, or a certain length for a (2) tel: or (3) sms: NDEF URI.
ModificadaBaja (2.6)1.6%—Nokia 6131 NFC2/1/200916/6/2026
The SmartPoster implementation on the Nokia 6131 Near Field Communication (NFC) phone with 05.12 firmware does not properly display the URI record when the Title record contains a certain combination of space, CR (aka \r), and . (dot) characters, which allows remote attackers to trick a user into loading an arbitrary…
ModificadaAlta (10)5.9%—Nokia Series 408/8/200816/6/2026
Multiple unspecified vulnerabilities in Nokia Series 40 3rd edition FP1, and possibly later devices, allow remote attackers to execute arbitrary code via unknown vectors, probably related to MIDP privilege escalation and persistent MIDlets, aka "ISSUES 11-15." NOTE: as of 20080807, the only disclosure is a vague…
ModificadaAlta (7.1)1.5%—Nokia N9515/12/200716/6/2026
Nokia N95 cell phone with RM-159 12.0.013 firmware allows remote attackers to cause a denial of service (device inoperability) via a SIP INVITE message accompanied by an immediately subsequent SIP CANCEL message, followed by a second SIP INVITE message in a different session.
ModificadaAlta (7.5)1.8%—Nokia Groupwise Mobile ServerNokia Intellisync Mobile SuiteNokia Intellisync Wireless Email Express11/5/200716/6/2026
usrmgr/userList.asp in Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allows remote attackers to modify user account details and cause a denial of service (account deactivation) via the userid parameter in…
ModificadaMedia (6.4)1.5%—Nokia Groupwise Mobile ServerNokia Intellisync Mobile SuiteNokia Intellisync Wireless Email Express11/5/200716/6/2026
Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allows remote attackers to obtain user names and other sensitive information via a direct request to (1) usrmgr/userList.asp or (2) usrmgr/userStatusList.asp.
ModificadaMedia (4.3)2.7%—Nokia Groupwise Mobile ServerNokia Intellisync Mobile SuiteNokia Intellisync Wireless Email Express11/5/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to…
ModificadaBaja (3.3)0.68%—Nokia N7026/1/200716/6/2026
The Nokia N70 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, as demonstrated by ussp-push.
ModificadaMedia (5)3.0%💥 ExploitNokia Symbian31/8/200616/6/2026
The Nokia Browser, possibly Nokia Symbian 60 Browser 3rd edition, allows remote attackers to cause a denial of service (crash) via JavaScript that constructs a large Unicode string.
ModificadaBaja (2.6)1.3%—Senokian Solutions Enterprise Groupware Systems27/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Enterprise Groupware System (EGS) 1.2.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the module parameter.
ModificadaAlta (7.8)4.6%💥 ExploitNokia N7019/2/200616/6/2026
Nokia N70 cell phone allows remote attackers to cause a denial of service (reboot or shutdown) through a wireless Bluetooth connection via a malformed Logical Link Control and Adaptation Protocol (L2CAP) packet whose length field is less than the actual length of the packet, possibly triggering a buffer overflow, as…
Orbitaley — Vulnerabilidades