Skip to main content

Vendor archive

nortel CVEs

Beta · best-effort

43 CVEs tagged to vendor nortel6 Critical, 17 High, 20 Medium, 0 Low, 0 Unrated.

CVE-2008-6579

Published Apr 1, 2009

Nortel Communication Server 1000 4.50.x allows remote attackers to obtain Web application structure via unknown vectors related to "web resources to phones and administrators."

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6578

Published Apr 1, 2009

Multiple unspecified vulnerabilities in Nortel Communication Server 1000 4.50.x allow remote attackers to execute arbitrary commands to gain privileges, obtain sensitive informati…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-6577

Published Apr 1, 2009

Nortel MG1000S, Signaling Server, and Call Server on the Communications Server 1000 (CS1K) 4.50.x contain multiple unspecified hard-coded accounts and passwords, which allows remo…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-6576

Published Apr 1, 2009

Unspecified vulnerability in the "session limitation technique" in the FTP service on Nortel Communications Server 1000 (CS1K) 4.50.x, when running on VGMC or signaling nodes, all…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5872

Published Jan 8, 2009

Multiple unspecified vulnerabilities in the UNIStim File Transfer Protocol (UFTP) processing in IP Client Manager (IPCM) in Nortel Multimedia Communication Server (MSC) 5100 3.0.1…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-4999

Published Nov 7, 2008

Nortel Networks UNIStim IP Phone 0604DAS allows remote attackers to cause a denial of service (crash) via a long ping packet ("ping of death"). NOTE: this issue could not be repr…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3157

Published Jul 11, 2008

Nortel SIP Multimedia PC Client 4.x MCS5100 and MCS5200 does not limit the number of concurrent sessions, which allows attackers to cause a denial of service (resource consumption…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2218

Published May 14, 2008

Buffer overflow in the Multimedia PC Client in Nortel Multimedia Communication Server (MCS) before Maintenance Release 3.5.8.3 and 4.0.25.3 allows remote attackers to cause a deni…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5636

Published Oct 23, 2007

Buffer overflow in the Nortel UNIStim IP Softphone 2050 allows remote attackers to cause a denial of service (application abort) and possibly execute arbitrary code via a flood of…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-3438

Published Jun 27, 2007

Buffer overflow in the SIP header parsing module in the Nortel PC Client SIP Soft Phone 4.1 3.5.208[20051015] allows remote attackers to execute arbitrary code via a malformed mes…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-3361

Published Jun 22, 2007

The Nortel PC Client SIP Soft Phone 4.1 3.5.208[20051015] allows remote attackers to cause a denial of service (device crash) via a SIP message with a malformed header.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-2886

Published May 30, 2007

Unspecified vulnerability in the Nortel CS 1000 M media card in Enterprise VoIP-Core-CS 1000E, 1000M, and 1000S 04.50W before 20070523 in Meridian/CS 1000 allows remote attackers…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2334

Published Apr 27, 2007

Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 5_05.149, 5_05.3xx before 5_05.304, and 6.x before 6_05.140 has two template HTML files lacking certain verific…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1820

Published Apr 2, 2007

Nortel Networks CallPilot and Meridian Mail voicemail systems, when a mailbox has auto logon enabled, allow remote attackers to retrieve or remove messages, or reconfigure the mai…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-6670

Published Dec 20, 2006

Unspecified vulnerability in Nortel CallPilot 4.x Server has unknown impact and attack vectors, aka P-2006-0011-GLOBAL.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 43 CVEsPage 1 of 2