Unrated severityNVD Advisory· Published Mar 22, 2015· Updated Jun 17, 2026
CVE-2015-0941
CVE-2015-0941
Description
The Inetc plugin for Nullsoft Scriptable Install System (NSIS), as used in CERT/CC Failure Observation Engine (FOE) and other products, does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and possibly execute arbitrary code by sending a crafted certificate in a download session for Windows executable files.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4(expand)+ 1 more
- (no CPE)
- cpe:2.3:a:inetc_project:inetc:*:*:*:*:*:nullsoft_scriptable_install_system:*:*
Patches
Vulnerability mechanics
References
1- www.kb.cert.org/vuls/id/894897nvdThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.