本页列出影响 nullsoft nullsoft_scriptable_install_system 的已公开 CVE 漏洞(通过 NVD CPE 关联)。每行包含严重程度评分、摘要与发布日期,便于识别与分析安全问题。
| CVE | 摘要 | 来源 | 最高 CVSS | EPSS % | 公开时间 | 更新时间 |
|---|---|---|---|---|---|---|
| CVE-2026-42171 | NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause my_GetTempFileName to return 0, as shown in the references). | [email protected] | 7.8 | 0.01% | 2026-04-24 | 2026-05-18 |
| CVE-2023-37378 | Nullsoft Scriptable Install System (NSIS) before 3.09 mishandles access control for an uninstaller directory. | [email protected] | 5.3 | 0.30% | 2023-07-03 | 2024-11-21 |
| CVE-2015-9268 | Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linking against Version.dll. In other words, there is no protection mechanism in which a wrapper function resolves the dependency at an appropriate time during runtime. | [email protected] | 7.8 | 0.58% | 2018-10-01 | 2024-11-21 |
| CVE-2015-9267 | Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder locations that allow unprivileged local users to overwrite files. This allows a local attack in which either a plugin or the uninstaller can be replaced by a Trojan horse program. | [email protected] | 5.5 | 0.04% | 2018-10-01 | 2024-11-21 |