Vulnerability index

Browse CVEs

38 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cs1000 HIGH 10.0
CVE-2008-6577

Nortel MG1000S, Signaling Server, and Call Server on the Communications Server 1000 (CS1K) 4.50.x contain multiple unspecified hard-coded accounts an…

Mitigation only
Fix from $1,950 2009-04-01
Cs1000 HIGH 10.0
CVE-2008-6578

Multiple unspecified vulnerabilities in Nortel Communication Server 1000 4.50.x allow remote attackers to execute arbitrary commands to gain privileg…

No fix yet
Fix from $1,950 2009-04-01
Cs1000 HIGH 7.8
CVE-2008-6576

Unspecified vulnerability in the "session limitation technique" in the FTP service on Nortel Communications Server 1000 (CS1K) 4.50.x, when running o…

Mitigation only
Fix from $1,950 2009-04-01
Cs1000 MEDIUM 5.0
CVE-2008-6579

Nortel Communication Server 1000 4.50.x allows remote attackers to obtain Web application structure via unknown vectors related to "web resources to …

Mitigation only
Fix from $1,600 2009-04-01
Communication Server 1000 HIGH 7.6
CVE-2008-6564

Nortel UNIStim protocol, as used in Communication Server 1000 and other products, uses predictable sequence numbers, which allows remote attackers to…

Mitigation only
Fix from $1,950 2009-03-31
Multimedia Communication Server 5100 HIGH 7.8
CVE-2008-5872

Multiple unspecified vulnerabilities in the UNIStim File Transfer Protocol (UFTP) processing in IP Client Manager (IPCM) in Nortel Multimedia Communi…

Mitigation only
Fix from $1,950 2009-01-08
Multimedia Communication Server 5100 MEDIUM 6.4
CVE-2008-5871

Nortel Multimedia Communication Server (MSC) 5100 3.0.13 does not verify credentials during call placement, which allows remote attackers to spoof an…

Mitigation only
Fix from $1,600 2009-01-08
Unistim Ip Phone HIGH 7.8
CVE-2008-4999

Nortel Networks UNIStim IP Phone 0604DAS allows remote attackers to cause a denial of service (crash) via a long ping packet ("ping of death"). NOTE…

No fix yet
Fix from $1,950 2008-11-07
Sip Multimedia Pc Client MEDIUM 5.0
CVE-2008-3157

Nortel SIP Multimedia PC Client 4.x MCS5100 and MCS5200 does not limit the number of concurrent sessions, which allows attackers to cause a denial of…

Mitigation only
Fix from $1,600 2008-07-11
Multimedia Communications Server MEDIUM 5.0
CVE-2008-2218

Buffer overflow in the Multimedia PC Client in Nortel Multimedia Communication Server (MCS) before Maintenance Release 3.5.8.3 and 4.0.25.3 allows re…

Fix: after 4.0.25.3
Fix from $1,600 2008-05-14
Ip Softphone 2050 HIGH 7.5
CVE-2007-5636EPSS 7%

Buffer overflow in the Nortel UNIStim IP Softphone 2050 allows remote attackers to cause a denial of service (application abort) and possibly execute…

No fix yet
Fix from $1,950 2007-10-23
Ip Softphone 2050 HIGH 7.1
CVE-2007-5639

The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and other Nortel IP Phone, Mobile Voice Client, and WLAN Handsets products allow remote attacke…

Patch available
Fix from $1,950 2007-10-23
Business Communications Manager HIGH 7.1
CVE-2007-5640

The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), Mobile…

Patch available
Fix from $1,950 2007-10-23
Meridian Option 11c HIGH 7.8
CVE-2007-5591

The CS1000 signaling server in Nortel Enterprise VoIP-Core-CS 1000M Chassis/Cabinet, Enterprise VoIP-Core-CS 1000E and 1000S, Meridian-Core-Option 11…

Mitigation only
Fix from $1,950 2007-10-19
Sip Softphone HIGH 7.8
CVE-2007-3438

Buffer overflow in the SIP header parsing module in the Nortel PC Client SIP Soft Phone 4.1 3.5.208[20051015] allows remote attackers to execute arbi…

Mitigation only
Fix from $1,950 2007-06-27
Pc Client Soft Phone Sip HIGH 7.8
CVE-2007-3361

The Nortel PC Client SIP Soft Phone 4.1 3.5.208[20051015] allows remote attackers to cause a denial of service (device crash) via a SIP message with …

Mitigation only
Fix from $1,950 2007-06-22
Communications Server MEDIUM 5.0
CVE-2007-2886

Unspecified vulnerability in the Nortel CS 1000 M media card in Enterprise VoIP-Core-CS 1000E, 1000M, and 1000S 04.50W before 20070523 in Meridian/CS…

Patch available
Fix from $1,600 2007-05-30
Contivity HIGH 10.0
CVE-2007-2333

Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 5_05.149, 5_05.3xx before 5_05.304, and 6.x before 6_05.140 includes the FIPSecry…

Patch available
Fix from $1,950 2007-04-27
Vpn Router 1010 HIGH 9.0
CVE-2007-2332

Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 6_05.140 uses a fixed DES key to encrypt passwords, which allows remote authentic…

Mitigation only
Fix from $1,950 2007-04-27
Contivity HIGH 7.5
CVE-2007-2334

Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 5_05.149, 5_05.3xx before 5_05.304, and 6.x before 6_05.140 has two template HTML…

Patch available
Fix from $1,950 2007-04-27
Callpilot HIGH 9.3
CVE-2007-1820

Nortel Networks CallPilot and Meridian Mail voicemail systems, when a mailbox has auto logon enabled, allow remote attackers to retrieve or remove me…

Mitigation only
Fix from $1,950 2007-04-02
Net Direct Client MEDIUM 6.9
CVE-2007-1057

The Net Direct client for Linux before 6.0.5 in Nortel Application Switch 2424, VPN 3050 and 3070, and SSL VPN Module 1000 extracts and executes file…

Fix: after 6.0.4
Fix from $1,600 2007-02-21
Callpilot Server HIGH 10.0
CVE-2006-6670

Unspecified vulnerability in Nortel CallPilot 4.x Server has unknown impact and attack vectors, aka P-2006-0011-GLOBAL.

Patch available
Fix from $1,950 2006-12-20
Ssl Vpn HIGH 7.5
CVE-2005-4197EPSS 12%

tunnelform.yaws in Nortel SSL VPN 4.2.1.6 allows remote attackers to execute arbitrary commands via a link in the a parameter, which is executed with…

Fix: after 4.2.1.6
Fix from $1,950 2005-12-13
Contivity HIGH 7.2
CVE-2005-2579

Nortel Contivity VPN Client V05_01.030, when configuring a certificate to be used as authentication, does not properly drop system privileges, which …

Mitigation only
Fix from $1,950 2005-08-16
Contivity MEDIUM 5.0
CVE-2005-1802

Nortel VPN Router (aka Contivity) allows remote attackers to cause a denial of service (crash) via an IPsec IKE packet with a malformed ISAKMP header.

Patch available
Fix from $1,600 2005-05-27
Contivity MEDIUM 5.0
CVE-2004-1105

Nortel Networks Contivity VPN Client displays a different error message depending on whether the username is valid or invalid, which could allow remo…

Patch available
Fix from $1,600 2005-01-10
Wlan Access Point 2220 MEDIUM 5.0
CVE-2004-2549EPSS 10%

Nortel Wireless LAN (WLAN) Access Point (AP) 2220, 2221, and 2225 allow remote attackers to cause a denial of service (service crash) via a TCP reque…

No fix yet
Fix from $1,600 2004-12-31
Ip Softphone 2050 MEDIUM 5.0
CVE-2004-1305EPSS 59%

The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers…

Patch available
Fix from $1,600 2004-12-23
Ip Softphone 2050 MEDIUM 5.0
CVE-2004-1319EPSS 27%

The DHTML Edit Control (dhtmled.ocx) allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, openin…

Patch available
Fix from $1,600 2004-12-15