NASM
by Nasm
Source repositories
CVEs (39)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-41420 | Med | 0.36 | 5.5 | 0.00 | Oct 3, 2022 | nasm v2.16 was discovered to contain a stack overflow in the Ndisasm component | ||
| CVE-2021-33452 | Med | 0.36 | 5.5 | 0.00 | Jul 26, 2022 | An issue was discovered in NASM version 2.16rc0. There are memory leaks in nasm_malloc() in nasmlib/alloc.c. | ||
| CVE-2021-33450 | Med | 0.36 | 5.5 | 0.00 | Jul 26, 2022 | An issue was discovered in NASM version 2.16rc0. There are memory leaks in nasm_calloc() in nasmlib/alloc.c. | ||
| CVE-2021-45257 | Med | 0.36 | 5.5 | 0.01 | Dec 22, 2021 | An infinite loop vulnerability exists in nasm 2.16rc0 via the gpaste_tokens function. | ||
| CVE-2021-45256 | Med | 0.36 | 5.5 | 0.01 | Dec 22, 2021 | A Null Pointer Dereference vulnerability existfs in nasm 2.16rc0 via asm/preproc.c. | ||
| CVE-2019-7147 | Med | 0.36 | 5.5 | 0.01 | Jan 29, 2019 | A buffer over-read exists in the function crc64ib in crc64.c in nasmlib in Netwide Assembler (NASM) 2.14rc16. A crafted asm input can cause segmentation faults, leading to denial-of-service. | ||
| CVE-2019-6291 | Med | 0.36 | 5.5 | 0.01 | Jan 15, 2019 | An issue was discovered in the function expr6 in eval.c in Netwide Assembler (NASM) through 2.14.02. There is a stack exhaustion problem caused by the expr6 function making recursive calls to itself in certain scenarios involving lots of '!' or '+' or '-' characters. Remote… | ||
| CVE-2019-6290 | Med | 0.36 | 5.5 | 0.01 | Jan 15, 2019 | An infinite recursion issue was discovered in eval.c in Netwide Assembler (NASM) through 2.14.02. There is a stack exhaustion problem resulting from infinite recursion in the functions expr, rexp, bexpr and cexpr in certain scenarios involving lots of '{' characters. Remote… | ||
| CVE-2018-20538 | Med | 0.36 | 5.5 | 0.01 | Dec 28, 2018 | There is a use-after-free at asm/preproc.c (function pp_getline) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service during certain finishes tests. | ||
| CVE-2018-20535 | Med | 0.36 | 5.5 | 0.01 | Dec 28, 2018 | There is a use-after-free at asm/preproc.c (function pp_getline) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service during a line-number increment attempt. | ||
| CVE-2018-1000886 | Med | 0.36 | 5.5 | 0.01 | Dec 20, 2018 | nasm version 2.14.01rc5, 2.15 contains a Buffer Overflow vulnerability in asm/stdscan.c:130 that can result in Stack-overflow caused by triggering endless macro generation, crash the program. This attack appear to be exploitable via a crafted nasm input file. | ||
| CVE-2018-19755 | Med | 0.36 | 5.5 | 0.01 | Nov 30, 2018 | There is an illegal address access at asm/preproc.c (function: is_mmacro) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service (out-of-bounds array access) because a certain conversion can result in a negative integer. | ||
| CVE-2018-19213 | Med | 0.36 | 5.5 | 0.01 | Nov 12, 2018 | Netwide Assembler (NASM) through 2.14rc16 has memory leaks that may lead to DoS, related to nasm_malloc in nasmlib/malloc.c. | ||
| CVE-2018-19209 | Med | 0.36 | 5.5 | 0.01 | Nov 12, 2018 | Netwide Assembler (NASM) 2.14rc15 has a NULL pointer dereference in the function find_label in asm/labels.c that will lead to a DoS attack. | ||
| CVE-2018-16999 | Med | 0.36 | 5.5 | 0.01 | Sep 13, 2018 | Netwide Assembler (NASM) 2.14rc15 has an invalid memory write (segmentation fault) in expand_smacro in preproc.c, which allows attackers to cause a denial of service via a crafted input file. | ||
| CVE-2018-1000667 | Med | 0.36 | 5.5 | 0.01 | Sep 6, 2018 | NASM nasm-2.13.03 nasm- 2.14rc15 version 2.14rc15 and earlier contains a memory corruption (crashed) of nasm when handling a crafted file due to function assemble_file(inname, depend_ptr) at asm/nasm.c:482. vulnerability in function assemble_file(inname, depend_ptr) at… | ||
| CVE-2018-10316 | Med | 0.36 | 5.5 | 0.01 | Apr 24, 2018 | Netwide Assembler (NASM) 2.14rc0 has an endless while loop in the assemble_file function of asm/nasm.c because of a globallineno integer overflow. | ||
| CVE-2004-1287 | 0.04 | — | 0.18 | Jan 10, 2005 | Buffer overflow in the error function in preproc.c for NASM 0.98.38 1.2 allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2005-1194. | |||
| CVE-2005-1194 | 0.00 | — | 0.01 | May 4, 2005 | Stack-based buffer overflow in the ieee_putascii function for nasm 0.98 and earlier allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2004-1287. |
- risk 0.36cvss 5.5epss 0.00
nasm v2.16 was discovered to contain a stack overflow in the Ndisasm component
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in NASM version 2.16rc0. There are memory leaks in nasm_malloc() in nasmlib/alloc.c.
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in NASM version 2.16rc0. There are memory leaks in nasm_calloc() in nasmlib/alloc.c.
- risk 0.36cvss 5.5epss 0.01
An infinite loop vulnerability exists in nasm 2.16rc0 via the gpaste_tokens function.
- risk 0.36cvss 5.5epss 0.01
A Null Pointer Dereference vulnerability existfs in nasm 2.16rc0 via asm/preproc.c.
- risk 0.36cvss 5.5epss 0.01
A buffer over-read exists in the function crc64ib in crc64.c in nasmlib in Netwide Assembler (NASM) 2.14rc16. A crafted asm input can cause segmentation faults, leading to denial-of-service.
- risk 0.36cvss 5.5epss 0.01
An issue was discovered in the function expr6 in eval.c in Netwide Assembler (NASM) through 2.14.02. There is a stack exhaustion problem caused by the expr6 function making recursive calls to itself in certain scenarios involving lots of '!' or '+' or '-' characters. Remote…
- risk 0.36cvss 5.5epss 0.01
An infinite recursion issue was discovered in eval.c in Netwide Assembler (NASM) through 2.14.02. There is a stack exhaustion problem resulting from infinite recursion in the functions expr, rexp, bexpr and cexpr in certain scenarios involving lots of '{' characters. Remote…
- risk 0.36cvss 5.5epss 0.01
There is a use-after-free at asm/preproc.c (function pp_getline) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service during certain finishes tests.
- risk 0.36cvss 5.5epss 0.01
There is a use-after-free at asm/preproc.c (function pp_getline) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service during a line-number increment attempt.
- risk 0.36cvss 5.5epss 0.01
nasm version 2.14.01rc5, 2.15 contains a Buffer Overflow vulnerability in asm/stdscan.c:130 that can result in Stack-overflow caused by triggering endless macro generation, crash the program. This attack appear to be exploitable via a crafted nasm input file.
- risk 0.36cvss 5.5epss 0.01
There is an illegal address access at asm/preproc.c (function: is_mmacro) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service (out-of-bounds array access) because a certain conversion can result in a negative integer.
- risk 0.36cvss 5.5epss 0.01
Netwide Assembler (NASM) through 2.14rc16 has memory leaks that may lead to DoS, related to nasm_malloc in nasmlib/malloc.c.
- risk 0.36cvss 5.5epss 0.01
Netwide Assembler (NASM) 2.14rc15 has a NULL pointer dereference in the function find_label in asm/labels.c that will lead to a DoS attack.
- risk 0.36cvss 5.5epss 0.01
Netwide Assembler (NASM) 2.14rc15 has an invalid memory write (segmentation fault) in expand_smacro in preproc.c, which allows attackers to cause a denial of service via a crafted input file.
- risk 0.36cvss 5.5epss 0.01
NASM nasm-2.13.03 nasm- 2.14rc15 version 2.14rc15 and earlier contains a memory corruption (crashed) of nasm when handling a crafted file due to function assemble_file(inname, depend_ptr) at asm/nasm.c:482. vulnerability in function assemble_file(inname, depend_ptr) at…
- risk 0.36cvss 5.5epss 0.01
Netwide Assembler (NASM) 2.14rc0 has an endless while loop in the assemble_file function of asm/nasm.c because of a globallineno integer overflow.
- CVE-2004-1287Jan 10, 2005risk 0.04cvss —epss 0.18
Buffer overflow in the error function in preproc.c for NASM 0.98.38 1.2 allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2005-1194.
- CVE-2005-1194May 4, 2005risk 0.00cvss —epss 0.01
Stack-based buffer overflow in the ieee_putascii function for nasm 0.98 and earlier allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2004-1287.
Page 2 of 2