NASM records
75 published records for vendor nasm.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 62.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-125 Out-of-bounds Read13
- CWE-416 Use After Free13
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer10
- CWE-787 Out-of-bounds Write9
- CWE-476 NULL Pointer Dereference9
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')3
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
75 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
45Plan | CVE-2004-1287Proof of concept | Buffer overflow in the error function in preproc.c for NASM 0.98.38 1.2 allows attackers to execute arbitrary code via a crafted asm file, anasm · netwide assembler · CWE-787 | Critical10.0 | — | 17.9% | Jan 10, 2005 |
39Monitor | CVE-2020-24978No exploit | In NASM 2.15.04rc3, there is a double-free vulnerability in pp_tokline asm/preproc.c.nasm · netwide assembler · CWE-415 | Critical9.8 | — | 1.4% | Sep 3, 2020 |
38Monitor | CVE-2008-7177No exploit | Buffer overflow in the listing module in Netwide Assembler (NASM) before 2.03.01 has unknown impact and attack vectors, a different vulnerabnasm · netwide assembler · CWE-119 | Critical9.3 | — | 2.4% | Sep 8, 2009 |
38Monitor | CVE-2026-6068No exploit | NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in thenasm · netwide assembler · CWE-416 | Critical9.6 | — | 0.5% | Apr 10, 2026 |
32Monitor | CVE-2017-10686No exploit | In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vulnerabilities in the tool nasm.nasm · netwide assembler · CWE-416 | High7.8 | — | 2.9% | Jun 29, 2017 |
32Monitor | CVE-2017-11111No exploit | In Netwide Assembler (NASM) 2.14rc0, preproc.c allows remote attackers to cause a denial of service (heap-based buffer overflow and applicatnasm · netwide assembler · CWE-119 | High7.8 | — | 1.7% | Jul 8, 2017 |
31Monitor | CVE-2017-17818No exploit | In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer over-read that will cause a remote denial of service attack, related to a nasm · netwide assembler · CWE-125 | High7.5 | — | 2.7% | Dec 20, 2017 |
31Monitor | CVE-2018-10254No exploit | Netwide Assembler (NASM) 2.13 has a stack-based buffer over-read in the disasm function of the disasm/disasm.c file.nasm · netwide assembler · CWE-125 | High7.8 | — | 1.4% | Apr 21, 2018 |
31Monitor | CVE-2018-19214No exploit | Netwide Assembler (NASM) 2.14rc15 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for insufficient input.nasm · netwide assembler · CWE-125 | High7.8 | — | 1.3% | Nov 12, 2018 |
31Monitor | CVE-2018-19216No exploit | Netwide Assembler (NASM) before 2.13.02 has a use-after-free in detoken at asm/preproc.c.nasm · netwide assembler · CWE-416 | High7.8 | — | 1.3% | Nov 12, 2018 |
31Monitor | CVE-2018-19215No exploit | Netwide Assembler (NASM) 2.14rc16 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for the special cases of the % annasm · netwide assembler · CWE-125 | High7.8 | — | 1.2% | Nov 12, 2018 |
31Monitor | CVE-2019-8343No exploit | In Netwide Assembler (NASM) 2.14.02, there is a use-after-free in paste_tokens in asm/preproc.c.nasm · netwide assembler · CWE-416 | High7.8 | — | 1.1% | Feb 15, 2019 |
31Monitor | CVE-2022-44370No exploit | NASM v2.16 was discovered to contain a heap buffer overflow in the component quote_for_pmake() asm/nasm.c:856nasm · netwide assembler · CWE-787 | High7.8 | — | 0.4% | Mar 29, 2023 |
31Monitor | CVE-2018-8883No exploit | Netwide Assembler (NASM) 2.13.02rc2 has a buffer over-read in the parse_line function in asm/parser.c via uncontrolled access to nasm_reg_flnasm · netwide assembler · CWE-125 | High7.8 | — | 0.4% | Mar 20, 2018 |
31Monitor | CVE-2018-8882No exploit | Netwide Assembler (NASM) 2.13.02rc2 has a stack-based buffer under-read in the function ieee_shr in asm/float.c via a large shift value.nasm · netwide assembler · CWE-119 | High7.8 | — | 0.4% | Mar 20, 2018 |
31Monitor | CVE-2023-31722No exploit | There exists a heap buffer overflow in nasm 2.16.02rc1 (GitHub commit: b952891).nasm · netwide assembler · CWE-787 | High7.8 | — | 0.4% | May 17, 2023 |
30Monitor | CVE-2008-2719Proof of concept | Off-by-one error in the ppscan function (preproc.c) in Netwide Assembler (NASM) 2.02 allows context-dependent attackers to cause a denial ofnasm · netwide assembler · CWE-189 | Medium6.8 | — | 10.5% | Jun 16, 2008 |
30Monitor | CVE-2026-6069No exploit | NASM’s disasm() function contains a stack based buffer overflow when formatting disassembly output, allowing an attacker triggered out-of-bonasm · netwide assembler · CWE-787 | High7.5 | — | 0.5% | Apr 10, 2026 |
29Monitor | CVE-2018-8881No exploit | Netwide Assembler (NASM) 2.13.02rc2 has a heap-based buffer over-read in the function tokenize in asm/preproc.c, related to an unterminated nasm · netwide assembler · CWE-125 | High7.3 | — | 1.1% | Mar 20, 2018 |
28Monitor | CVE-2019-20352No exploit | In Netwide Assembler (NASM) 2.15rc0, a heap-based buffer over-read occurs (via a crafted .asm file) in set_text_free when called from expandnasm · netwide assembler · CWE-125 | High7.1 | — | 0.8% | Jan 6, 2020 |
24Monitor | CVE-2018-16517Proof of concept | asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a denial of service via a nasm · netwide assembler · CWE-476 | Medium5.5 | — | 5.2% | Sep 6, 2018 |
24Monitor | CVE-2022-46456No exploit | NASM v2.16 was discovered to contain a global buffer overflow in the component dbgdbg_typevalue at /output/outdbg.c.nasm · netwide assembler · CWE-120 | Medium6.1 | — | 0.4% | Jan 4, 2023 |
22Monitor | CVE-2017-17815No exploit | In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in is_mmacro() in asm/preproc.c that will cause a remote denial of snasm · netwide assembler · CWE-754 | Medium5.5 | — | 1.5% | Dec 20, 2017 |
22Monitor | CVE-2017-17810No exploit | In Netwide Assembler (NASM) 2.14rc0, there is a "SEGV on unknown address" that will cause a remote denial of service attack, because asm/prenasm · netwide assembler · CWE-20 | Medium5.5 | — | 1.5% | Dec 20, 2017 |
22Monitor | CVE-2017-17812No exploit | In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer over-read in the function detoken() in asm/preproc.c that will cause a remnasm · netwide assembler · CWE-125 | Medium5.5 | — | 1.5% | Dec 20, 2017 |
- CVE-2004-128745Plan
Buffer overflow in the error function in preproc.c for NASM 0.98.38 1.2 allows attackers to execute arbitrary code via a crafted asm file, a
CriticalCVSS 10.0Proof of conceptEPSS 18%nasm · netwide assemblerJan 10, 2005
- CVE-2020-2497839Monitor
In NASM 2.15.04rc3, there is a double-free vulnerability in pp_tokline asm/preproc.c.
CriticalCVSS 9.8No exploitEPSS 1%nasm · netwide assemblerSep 3, 2020
- CVE-2008-717738Monitor
Buffer overflow in the listing module in Netwide Assembler (NASM) before 2.03.01 has unknown impact and attack vectors, a different vulnerab
CriticalCVSS 9.3No exploitEPSS 2%nasm · netwide assemblerSep 8, 2009
- CVE-2026-606838Monitor
NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the
CriticalCVSS 9.6No exploitEPSS 0%nasm · netwide assemblerApr 10, 2026
- CVE-2017-1068632Monitor
In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vulnerabilities in the tool nasm.
HighCVSS 7.8No exploitEPSS 3%nasm · netwide assemblerJun 29, 2017
- CVE-2017-1111132Monitor
In Netwide Assembler (NASM) 2.14rc0, preproc.c allows remote attackers to cause a denial of service (heap-based buffer overflow and applicat
HighCVSS 7.8No exploitEPSS 2%nasm · netwide assemblerJul 8, 2017
- CVE-2017-1781831Monitor
In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer over-read that will cause a remote denial of service attack, related to a
HighCVSS 7.5No exploitEPSS 3%nasm · netwide assemblerDec 20, 2017
- CVE-2018-1025431Monitor
Netwide Assembler (NASM) 2.13 has a stack-based buffer over-read in the disasm function of the disasm/disasm.c file.
HighCVSS 7.8No exploitEPSS 1%nasm · netwide assemblerApr 21, 2018
- CVE-2018-1921431Monitor
Netwide Assembler (NASM) 2.14rc15 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for insufficient input.
HighCVSS 7.8No exploitEPSS 1%nasm · netwide assemblerNov 12, 2018
- CVE-2018-1921631Monitor
Netwide Assembler (NASM) before 2.13.02 has a use-after-free in detoken at asm/preproc.c.
HighCVSS 7.8No exploitEPSS 1%nasm · netwide assemblerNov 12, 2018
- CVE-2018-1921531Monitor
Netwide Assembler (NASM) 2.14rc16 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for the special cases of the % an
HighCVSS 7.8No exploitEPSS 1%nasm · netwide assemblerNov 12, 2018
- CVE-2019-834331Monitor
In Netwide Assembler (NASM) 2.14.02, there is a use-after-free in paste_tokens in asm/preproc.c.
HighCVSS 7.8No exploitEPSS 1%nasm · netwide assemblerFeb 15, 2019
- CVE-2022-4437031Monitor
NASM v2.16 was discovered to contain a heap buffer overflow in the component quote_for_pmake() asm/nasm.c:856
HighCVSS 7.8No exploitEPSS 0%nasm · netwide assemblerMar 29, 2023
- CVE-2018-888331Monitor
Netwide Assembler (NASM) 2.13.02rc2 has a buffer over-read in the parse_line function in asm/parser.c via uncontrolled access to nasm_reg_fl
HighCVSS 7.8No exploitEPSS 0%nasm · netwide assemblerMar 20, 2018
- CVE-2018-888231Monitor
Netwide Assembler (NASM) 2.13.02rc2 has a stack-based buffer under-read in the function ieee_shr in asm/float.c via a large shift value.
HighCVSS 7.8No exploitEPSS 0%nasm · netwide assemblerMar 20, 2018
- CVE-2023-3172231Monitor
There exists a heap buffer overflow in nasm 2.16.02rc1 (GitHub commit: b952891).
HighCVSS 7.8No exploitEPSS 0%nasm · netwide assemblerMay 17, 2023
- CVE-2008-271930Monitor
Off-by-one error in the ppscan function (preproc.c) in Netwide Assembler (NASM) 2.02 allows context-dependent attackers to cause a denial of
MediumCVSS 6.8Proof of conceptEPSS 10%nasm · netwide assemblerJun 16, 2008
- CVE-2026-606930Monitor
NASM’s disasm() function contains a stack based buffer overflow when formatting disassembly output, allowing an attacker triggered out-of-bo
HighCVSS 7.5No exploitEPSS 0%nasm · netwide assemblerApr 10, 2026
- CVE-2018-888129Monitor
Netwide Assembler (NASM) 2.13.02rc2 has a heap-based buffer over-read in the function tokenize in asm/preproc.c, related to an unterminated
HighCVSS 7.3No exploitEPSS 1%nasm · netwide assemblerMar 20, 2018
- CVE-2019-2035228Monitor
In Netwide Assembler (NASM) 2.15rc0, a heap-based buffer over-read occurs (via a crafted .asm file) in set_text_free when called from expand
HighCVSS 7.1No exploitEPSS 1%nasm · netwide assemblerJan 6, 2020
- CVE-2018-1651724Monitor
asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a denial of service via a
MediumCVSS 5.5Proof of conceptEPSS 5%nasm · netwide assemblerSep 6, 2018
- CVE-2022-4645624Monitor
NASM v2.16 was discovered to contain a global buffer overflow in the component dbgdbg_typevalue at /output/outdbg.c.
MediumCVSS 6.1No exploitEPSS 0%nasm · netwide assemblerJan 4, 2023
- CVE-2017-1781522Monitor
In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in is_mmacro() in asm/preproc.c that will cause a remote denial of s
MediumCVSS 5.5No exploitEPSS 1%nasm · netwide assemblerDec 20, 2017
- CVE-2017-1781022Monitor
In Netwide Assembler (NASM) 2.14rc0, there is a "SEGV on unknown address" that will cause a remote denial of service attack, because asm/pre
MediumCVSS 5.5No exploitEPSS 1%nasm · netwide assemblerDec 20, 2017
- CVE-2017-1781222Monitor
In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer over-read in the function detoken() in asm/preproc.c that will cause a rem
MediumCVSS 5.5No exploitEPSS 1%nasm · netwide assemblerDec 20, 2017