
CVE-2007-2332
https://notcve.org/view.php?id=CVE-2007-2332
27 Apr 2007 — Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 6_05.140 uses a fixed DES key to encrypt passwords, which allows remote authenticated users to obtain a password via a brute force attack on a hash from the LDAP store. Nortel VPN Router (también conocido como Contivity) 1000, 2000, 4000, y 5000 anterior a 6_05.140 utiliza una llave DES para encriptar contraseñas, lo cual permite a usuarios remotos validados obtener una contraseña a través de ataques por fuerza bruta sobre un hash desde el ... • http://secunia.com/advisories/24962 •

CVE-2007-2333
https://notcve.org/view.php?id=CVE-2007-2333
27 Apr 2007 — Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 5_05.149, 5_05.3xx before 5_05.304, and 6.x before 6_05.140 includes the FIPSecryptedtest1219 and FIPSunecryptedtest1219 default accounts in the LDAP template, which might allow remote attackers to access the private network. Nortel VPN Router (también conocido como Contivity) 1000, 2000, 4000, y 5000 anterior a 5_05.149, 5_05.3xx anterior 5_05.304, y 6.x anterior 6_05.140 incluyen las cuentas por defecto FIPSecryptedtest1219 y FIPSunecrypt... • http://osvdb.org/35055 •

CVE-2007-2334
https://notcve.org/view.php?id=CVE-2007-2334
27 Apr 2007 — Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 5_05.149, 5_05.3xx before 5_05.304, and 6.x before 6_05.140 has two template HTML files lacking certain verification tags, which allows remote attackers to access the administration interface and change the device configuration via certain requests. Nortel VPN Router (también conocido como Contivity) 1000, 2000, 4000, y 5000 anterior a 5_05.149, 5_05.3xx anterior 5_05.304, y 6.x anterior 6_05.140 tiene dos archivos de plantilla html que car... • http://osvdb.org/35056 •

CVE-2007-1820
https://notcve.org/view.php?id=CVE-2007-1820
02 Apr 2007 — Nortel Networks CallPilot and Meridian Mail voicemail systems, when a mailbox has auto logon enabled, allow remote attackers to retrieve or remove messages, or reconfigure the mailbox, by spoofing Calling Number Identification (CNID, aka Caller ID). Los sistemas de email por voz Nortel Networks CallPilot y Meridian Mail, cuando la bandeja de entrada tiene activado la auto entrada, permite a atacantes remotos recuperar o borrar mensajes, o reconfigurar la bandeja de entrada, a través de la suplantación Calli... • http://osvdb.org/34983 •

CVE-2007-1057 – Nortel SSL VPN Linux Client 6.0.3 - Local Privilege Escalation
https://notcve.org/view.php?id=CVE-2007-1057
21 Feb 2007 — The Net Direct client for Linux before 6.0.5 in Nortel Application Switch 2424, VPN 3050 and 3070, and SSL VPN Module 1000 extracts and executes files with insecure permissions, which allows local users to exploit a race condition to replace a world-writable file in /tmp/NetClient and cause another user to execute arbitrary code when attempting to execute this client, as demonstrated by replacing /tmp/NetClient/client. El cliente Net Direct para Linux versiones anteriores a 6.0.5 de Nortel Application Switc... • https://www.exploit-db.com/exploits/3356 •

CVE-2006-6670
https://notcve.org/view.php?id=CVE-2006-6670
20 Dec 2006 — Unspecified vulnerability in Nortel CallPilot 4.x Server has unknown impact and attack vectors, aka P-2006-0011-GLOBAL. Vulnerabilidad no especificada en Nortel CallPilot 4.x Server tiene un impacto desconocido y ataques de vectores, también conocido como P-2006-0011-GLOBAL. • http://secunia.com/advisories/23403 •

CVE-2005-4197 – Nortel SSL VPN 4.2.1.6 - Web Interface Input Validation
https://notcve.org/view.php?id=CVE-2005-4197
13 Dec 2005 — tunnelform.yaws in Nortel SSL VPN 4.2.1.6 allows remote attackers to execute arbitrary commands via a link in the a parameter, which is executed with extra privileges in a cryptographically signed Java Applet. • https://www.exploit-db.com/exploits/26771 •

CVE-2005-2579
https://notcve.org/view.php?id=CVE-2005-2579
16 Aug 2005 — Nortel Contivity VPN Client V05_01.030, when configuring a certificate to be used as authentication, does not properly drop system privileges, which allows local users to gain privileges by opening a program with the File Open dialog box. • http://marc.info/?l=bugtraq&m=112370730131219&w=2 •

CVE-2005-0356 – TCP TIMESTAMPS - Denial of Service
https://notcve.org/view.php?id=CVE-2005-0356
31 May 2005 — Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old. • https://www.exploit-db.com/exploits/1008 •

CVE-2005-1802
https://notcve.org/view.php?id=CVE-2005-1802
27 May 2005 — Nortel VPN Router (aka Contivity) allows remote attackers to cause a denial of service (crash) via an IPsec IKE packet with a malformed ISAKMP header. • http://securitytracker.com/id?1014068 •