Skip to content
Noroxi

NASM records

75 published records for vendor nasm.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
3
With a fix record
62.7%
Median publish → KEV
No record has entered KEV

All records

75 records
  • Buffer overflow in the error function in preproc.c for NASM 0.98.38 1.2 allows attackers to execute arbitrary code via a crafted asm file, a

    CriticalCVSS 10.0Proof of conceptEPSS 18%

    nasm · netwide assemblerJan 10, 2005

  • In NASM 2.15.04rc3, there is a double-free vulnerability in pp_tokline asm/preproc.c.

    CriticalCVSS 9.8No exploitEPSS 1%

    nasm · netwide assemblerSep 3, 2020

  • CVE-2008-7177
    38Monitor

    Buffer overflow in the listing module in Netwide Assembler (NASM) before 2.03.01 has unknown impact and attack vectors, a different vulnerab

    CriticalCVSS 9.3No exploitEPSS 2%

    nasm · netwide assemblerSep 8, 2009

  • CVE-2026-6068
    38Monitor

    NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the

    CriticalCVSS 9.6No exploitEPSS 0%

    nasm · netwide assemblerApr 10, 2026

  • In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vulnerabilities in the tool nasm.

    HighCVSS 7.8No exploitEPSS 3%

    nasm · netwide assemblerJun 29, 2017

  • In Netwide Assembler (NASM) 2.14rc0, preproc.c allows remote attackers to cause a denial of service (heap-based buffer overflow and applicat

    HighCVSS 7.8No exploitEPSS 2%

    nasm · netwide assemblerJul 8, 2017

  • In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer over-read that will cause a remote denial of service attack, related to a

    HighCVSS 7.5No exploitEPSS 3%

    nasm · netwide assemblerDec 20, 2017

  • Netwide Assembler (NASM) 2.13 has a stack-based buffer over-read in the disasm function of the disasm/disasm.c file.

    HighCVSS 7.8No exploitEPSS 1%

    nasm · netwide assemblerApr 21, 2018

  • Netwide Assembler (NASM) 2.14rc15 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for insufficient input.

    HighCVSS 7.8No exploitEPSS 1%

    nasm · netwide assemblerNov 12, 2018

  • Netwide Assembler (NASM) before 2.13.02 has a use-after-free in detoken at asm/preproc.c.

    HighCVSS 7.8No exploitEPSS 1%

    nasm · netwide assemblerNov 12, 2018

  • Netwide Assembler (NASM) 2.14rc16 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for the special cases of the % an

    HighCVSS 7.8No exploitEPSS 1%

    nasm · netwide assemblerNov 12, 2018

  • CVE-2019-8343
    31Monitor

    In Netwide Assembler (NASM) 2.14.02, there is a use-after-free in paste_tokens in asm/preproc.c.

    HighCVSS 7.8No exploitEPSS 1%

    nasm · netwide assemblerFeb 15, 2019

  • NASM v2.16 was discovered to contain a heap buffer overflow in the component quote_for_pmake() asm/nasm.c:856

    HighCVSS 7.8No exploitEPSS 0%

    nasm · netwide assemblerMar 29, 2023

  • CVE-2018-8883
    31Monitor

    Netwide Assembler (NASM) 2.13.02rc2 has a buffer over-read in the parse_line function in asm/parser.c via uncontrolled access to nasm_reg_fl

    HighCVSS 7.8No exploitEPSS 0%

    nasm · netwide assemblerMar 20, 2018

  • CVE-2018-8882
    31Monitor

    Netwide Assembler (NASM) 2.13.02rc2 has a stack-based buffer under-read in the function ieee_shr in asm/float.c via a large shift value.

    HighCVSS 7.8No exploitEPSS 0%

    nasm · netwide assemblerMar 20, 2018

  • There exists a heap buffer overflow in nasm 2.16.02rc1 (GitHub commit: b952891).

    HighCVSS 7.8No exploitEPSS 0%

    nasm · netwide assemblerMay 17, 2023

  • CVE-2008-2719
    30Monitor

    Off-by-one error in the ppscan function (preproc.c) in Netwide Assembler (NASM) 2.02 allows context-dependent attackers to cause a denial of

    MediumCVSS 6.8Proof of conceptEPSS 10%

    nasm · netwide assemblerJun 16, 2008

  • CVE-2026-6069
    30Monitor

    NASM’s disasm() function contains a stack based buffer overflow when formatting disassembly output, allowing an attacker triggered out-of-bo

    HighCVSS 7.5No exploitEPSS 0%

    nasm · netwide assemblerApr 10, 2026

  • CVE-2018-8881
    29Monitor

    Netwide Assembler (NASM) 2.13.02rc2 has a heap-based buffer over-read in the function tokenize in asm/preproc.c, related to an unterminated

    HighCVSS 7.3No exploitEPSS 1%

    nasm · netwide assemblerMar 20, 2018

  • In Netwide Assembler (NASM) 2.15rc0, a heap-based buffer over-read occurs (via a crafted .asm file) in set_text_free when called from expand

    HighCVSS 7.1No exploitEPSS 1%

    nasm · netwide assemblerJan 6, 2020

  • asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a denial of service via a

    MediumCVSS 5.5Proof of conceptEPSS 5%

    nasm · netwide assemblerSep 6, 2018

  • NASM v2.16 was discovered to contain a global buffer overflow in the component dbgdbg_typevalue at /output/outdbg.c.

    MediumCVSS 6.1No exploitEPSS 0%

    nasm · netwide assemblerJan 4, 2023

  • In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in is_mmacro() in asm/preproc.c that will cause a remote denial of s

    MediumCVSS 5.5No exploitEPSS 1%

    nasm · netwide assemblerDec 20, 2017

  • In Netwide Assembler (NASM) 2.14rc0, there is a "SEGV on unknown address" that will cause a remote denial of service attack, because asm/pre

    MediumCVSS 5.5No exploitEPSS 1%

    nasm · netwide assemblerDec 20, 2017

  • In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer over-read in the function detoken() in asm/preproc.c that will cause a rem

    MediumCVSS 5.5No exploitEPSS 1%

    nasm · netwide assemblerDec 20, 2017