Skip to main content

Vendor/product archive

nasm / netwide_assembler CVEs

Beta · best-effort

75 CVEs tagged to nasm / netwide_assembler4 Critical, 15 High, 50 Medium, 6 Low, 0 Unrated.

CVE-2026-6069

Published Apr 10, 2026

NASM’s disasm() function contains a stack based buffer overflow when formatting disassembly output, allowing an attacker triggered out-of-bounds write when `slen` exceeds the buff…

CVSS 7.5 · High
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-6068

Published Apr 10, 2026

NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the global depend_file and later dereferen…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
22.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-6067

Published Apr 10, 2026

A heap buffer overflow vulnerability exists in the Netwide Assembler (NASM) due to a lack of bounds checking in the obj_directive() function. This vulnerability can be exploited b…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-8846

Published Aug 11, 2025

A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected is the function parse_line of the file parser.c. The manipulation leads to stack-based buffer overflow. T…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-8845

Published Aug 11, 2025

A vulnerability was identified in NASM Netwide Assember 2.17rc0. This issue affects the function assemble_file of the file nasm.c. The manipulation leads to stack-based buffer ove…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-8844

Published Aug 11, 2025

A vulnerability was determined in NASM Netwide Assember 2.17rc0. This vulnerability affects the function parse_smacro_template of the file preproc.c. The manipulation leads to nul…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-8843

Published Aug 11, 2025

A vulnerability was found in NASM Netwide Assember 2.17rc0. This affects the function macho_no_dead_strip of the file outmacho.c. The manipulation leads to heap-based buffer overf…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-8842

Published Aug 11, 2025

A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected by this issue is the function do_directive of the file preproc.c. The manipulation leads to use after fre…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-38668

Published Aug 22, 2023

Stack-based buffer over-read in disasm in nasm 2.16 allows attackers to cause a denial of service (crash).

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38667

Published Aug 22, 2023

Stack-based buffer over-read in function disasm in nasm 2.16 allows attackers to cause a denial of service.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38665

Published Aug 22, 2023

Null pointer dereference in ieee_write_file in nasm 2.16rc0 allows attackers to cause a denial of service (crash).

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29654

Published Aug 22, 2023

Buffer overflow vulnerability in quote_for_pmake in asm/nasm.c in nasm before 2.15.05 allows attackers to cause a denial of service via crafted file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-21687

Published Aug 22, 2023

Buffer Overflow vulnerability in scan function in stdscan.c in nasm 2.15rc0 allows remote attackers to cause a denial of service via crafted asm file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-21686

Published Aug 22, 2023

A stack-use-after-scope issue discovered in expand_mmac_params function in preproc.c in nasm before 2.15.04 allows remote attackers to cause a denial of service via crafted asm fi…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-21685

Published Aug 22, 2023

Buffer Overflow vulnerability in hash_findi function in hashtbl.c in nasm 2.15rc0 allows remote attackers to cause a denial of service via crafted asm file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-21528

Published Aug 22, 2023

A Segmentation Fault issue discovered in in ieee_segment function in outieee.c in nasm 2.14.03 and 2.15 allows remote attackers to cause a denial of service via crafted assembly f…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-18780

Published Aug 22, 2023

A Use After Free vulnerability in function new_Token in asm/preproc.c in nasm 2.14.02 allows attackers to cause a denial of service via crafted nasm command.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-44370

Published Mar 29, 2023

NASM v2.16 was discovered to contain a heap buffer overflow in the component quote_for_pmake() asm/nasm.c:856

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-46457

Published Jan 4, 2023

NASM v2.16 was discovered to contain a segmentation violation in the component ieee_write_file at /output/outieee.c.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-46456

Published Jan 4, 2023

NASM v2.16 was discovered to contain a global buffer overflow in the component dbgdbg_typevalue at /output/outdbg.c.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-33452

Published Jul 26, 2022

An issue was discovered in NASM version 2.16rc0. There are memory leaks in nasm_malloc() in nasmlib/alloc.c.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 75 CVEsPage 1 of 3