Debian Nsis vulnerabilities
4 known vulnerabilities affecting debian/nsis.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2025-43715P3HIGHCVSS 8.1fixed in nsis 3.11-1 (forky)2025
CVE-2025-43715 [HIGH] CVE-2025-43715: nsis - Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local us...
Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM during an installation, because the temporary plugins directory is created under %WINDIR%\temp and unprivileged users can place a crafted executable file by winning a race condition. This occurs because EW_CREATEDIR does not always set the CreateRestrict
debian
CVE-2015-9268P4HIGHCVSS 7.8fixed in nsis 2.50-1 (bookworm)2015
CVE-2015-9268 [HIGH] CVE-2015-9268: nsis - Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linkin...
Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linking against Version.dll. In other words, there is no protection mechanism in which a wrapper function resolves the dependency at an appropriate time during runtime.
Scope: local
bookworm: resolved (fixed in 2.50-1)
bullseye: resolved (fixed in 2.50-1)
forky: resolved (fixed in 2.50-1)
sid: reso
debian
CVE-2023-37378P4MEDIUMCVSS 5.3fixed in nsis 3.08-3+deb12u1 (bookworm)2023
CVE-2023-37378 [MEDIUM] CVE-2023-37378: nsis - Nullsoft Scriptable Install System (NSIS) before 3.09 mishandles access control ...
Nullsoft Scriptable Install System (NSIS) before 3.09 mishandles access control for an uninstaller directory.
Scope: local
bookworm: resolved (fixed in 3.08-3+deb12u1)
bullseye: resolved (fixed in 3.06.1-1+deb11u1)
forky: resolved (fixed in 3.09-1)
sid: resolved (fixed in 3.09-1)
trixie: resolved (fixed in 3.09-1)
debian
CVE-2015-9267P4MEDIUMCVSS 5.5fixed in nsis 2.50-1 (bookworm)2015
CVE-2015-9267 [MEDIUM] CVE-2015-9267: nsis - Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder loca...
Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder locations that allow unprivileged local users to overwrite files. This allows a local attack in which either a plugin or the uninstaller can be replaced by a Trojan horse program.
Scope: local
bookworm: resolved (fixed in 2.50-1)
bullseye: resolved (fixed in 2.50-1)
forky: resolved (fixed in 2.
debian