VendorsNASMnetwide_assemblerall versions
Vulnerabilities

NASM Netwide Assembler

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

75CVEs
CVE-2004-1287
Buffer overflow in the error function in preproc.c for NASM 0.98.38 1.2 allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2005-1194.
Published 2004-12-22 · Modified
10.01 PoCEPSS 0.179
CVE-2020-24978
In NASM 2.15.04rc3, there is a double-free vulnerability in pp_tokline asm/preproc.c. This is fixed in commit 8806c3ca007b84accac21dd88b900fb03614ceb7.
Published 2020-09-03 · Modified
9.8EPSS 0.014
CVE-2026-6068
CVE-2026-6068
Published 2026-04-10 · Analyzed
9.6EPSS 0.004
CVE-2008-7177
Buffer overflow in the listing module in Netwide Assembler (NASM) before 2.03.01 has unknown impact and attack vectors, a different vulnerability than CVE-2008-2719.
Published 2009-09-08 · Modified
9.3EPSS 0.024
CVE-2017-10686
In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vulnerabilities in the tool nasm. The related heap is allocated in the token() function and freed in the detoken() function (called by pp_getline()) - it is used again at multiple positions later that could cause multiple damages. For example, it causes a corrupted double-linked list in detoken(), a double free or corruption in delete_Token(), and an out-of-bounds write in detoken(). It has a high possibility to lead to a remote code execution attack.
Published 2017-06-29 · Modified
7.8EPSS 0.029
CVE-2017-11111
In Netwide Assembler (NASM) 2.14rc0, preproc.c allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.
Published 2017-07-08 · Modified
7.8EPSS 0.017
CVE-2018-10254
Netwide Assembler (NASM) 2.13 has a stack-based buffer over-read in the disasm function of the disasm/disasm.c file. Remote attackers could leverage this vulnerability to cause a denial of service or possibly have unspecified other impact via a crafted ELF file.
Published 2018-04-21 · Modified
7.8EPSS 0.014
CVE-2018-19214
Netwide Assembler (NASM) 2.14rc15 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for insufficient input.
Published 2018-11-12 · Modified
7.8EPSS 0.013
CVE-2018-19216
Netwide Assembler (NASM) before 2.13.02 has a use-after-free in detoken at asm/preproc.c.
Published 2018-11-12 · Modified
7.8EPSS 0.013
CVE-2018-19215
Netwide Assembler (NASM) 2.14rc16 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for the special cases of the % and $ and ! characters.
Published 2018-11-12 · Modified
7.8EPSS 0.012
CVE-2019-8343
In Netwide Assembler (NASM) 2.14.02, there is a use-after-free in paste_tokens in asm/preproc.c.
Published 2019-02-15 · Modified
7.8EPSS 0.011
CVE-2022-44370
NASM v2.16 was discovered to contain a heap buffer overflow in the component quote_for_pmake() asm/nasm.c:856
Published 2023-03-29 · Modified
7.8EPSS 0.004
CVE-2018-8883
Netwide Assembler (NASM) 2.13.02rc2 has a buffer over-read in the parse_line function in asm/parser.c via uncontrolled access to nasm_reg_flags.
Published 2018-03-20 · Modified
7.8EPSS 0.004
CVE-2018-8882
Netwide Assembler (NASM) 2.13.02rc2 has a stack-based buffer under-read in the function ieee_shr in asm/float.c via a large shift value.
Published 2018-03-20 · Modified
7.8EPSS 0.004
CVE-2022-46456
NASM v2.16 was discovered to contain a global buffer overflow in the component dbgdbg_typevalue at /output/outdbg.c.
Published 2023-01-04 · Modified
7.8EPSS 0.004
CVE-2023-31722
There exists a heap buffer overflow in nasm 2.16.02rc1 (GitHub commit: b952891).
Published 2023-05-17 · Modified
7.8EPSS 0.004
CVE-2025-8845
NASM Netwide Assember nasm.c assemble_file stack-based overflow
Published 2025-08-11 · Analyzed
7.8EPSS 0.003
CVE-2025-8846
NASM Netwide Assember parser.c parse_line stack-based overflow
Published 2025-08-11 · Analyzed
7.8EPSS 0.003
CVE-2025-8843
NASM Netwide Assember outmacho.c macho_no_dead_strip heap-based overflow
Published 2025-08-11 · Analyzed
7.8EPSS 0.003
CVE-2025-8842
NASM Netwide Assember preproc.c do_directive use after free
Published 2025-08-11 · Analyzed
7.8EPSS 0.002
CVE-2017-17818
In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer over-read that will cause a remote denial of service attack, related to a while loop in paste_tokens in asm/preproc.c.
Published 2017-12-21 · Modified
7.5EPSS 0.027
CVE-2026-6069
CVE-2026-6069
Published 2026-04-10 · Analyzed
7.5EPSS 0.004
CVE-2026-6067
CVE-2026-6067
Published 2026-04-10 · Analyzed
7.5EPSS 0.004
CVE-2018-8881
Netwide Assembler (NASM) 2.13.02rc2 has a heap-based buffer over-read in the function tokenize in asm/preproc.c, related to an unterminated string.
Published 2018-03-20 · Modified
7.3EPSS 0.011
CVE-2019-20352
In Netwide Assembler (NASM) 2.15rc0, a heap-based buffer over-read occurs (via a crafted .asm file) in set_text_free when called from expand_one_smacro in asm/preproc.c.
Published 2020-01-06 · Modified
7.1EPSS 0.008
CVE-2008-2719
Off-by-one error in the ppscan function (preproc.c) in Netwide Assembler (NASM) 2.02 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted file that triggers a stack-based buffer overflow.
Published 2008-06-16 · Modified
6.81 PoCEPSS 0.105
CVE-2018-16517
asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a denial of service via a crafted file.
Published 2018-09-06 · Modified
5.51 PoCEPSS 0.052
CVE-2017-17810
In Netwide Assembler (NASM) 2.14rc0, there is a "SEGV on unknown address" that will cause a remote denial of service attack, because asm/preproc.c mishandles macro calls that have the wrong number of arguments.
Published 2017-12-21 · Modified
5.5EPSS 0.015
CVE-2017-17812
In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer over-read in the function detoken() in asm/preproc.c that will cause a remote denial of service attack.
Published 2017-12-21 · Modified
5.5EPSS 0.015
CVE-2017-17815
In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in is_mmacro() in asm/preproc.c that will cause a remote denial of service attack, because of a missing check for the relationship between minimum and maximum parameter counts.
Published 2017-12-21 · Modified
5.5EPSS 0.015
CVE-2017-17817
In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in pp_verror in asm/preproc.c that will cause a remote denial of service attack.
Published 2017-12-21 · Modified
5.5EPSS 0.014
CVE-2017-17820
In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in pp_list_one_macro in asm/preproc.c that will lead to a remote denial of service attack, related to mishandling of operand-type errors.
Published 2017-12-21 · Modified
5.5EPSS 0.014
CVE-2017-17819
In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in the function find_cc() in asm/preproc.c that will cause a remote denial of service attack, because pointers associated with skip_white_ calls are not validated.
Published 2017-12-21 · Modified
5.5EPSS 0.014
CVE-2019-6291
An issue was discovered in the function expr6 in eval.c in Netwide Assembler (NASM) through 2.14.02. There is a stack exhaustion problem caused by the expr6 function making recursive calls to itself in certain scenarios involving lots of '!' or '+' or '-' characters. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted asm file.
Published 2019-01-15 · Modified
5.5EPSS 0.013
CVE-2019-6290
An infinite recursion issue was discovered in eval.c in Netwide Assembler (NASM) through 2.14.02. There is a stack exhaustion problem resulting from infinite recursion in the functions expr, rexp, bexpr and cexpr in certain scenarios involving lots of '{' characters. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted asm file.
Published 2019-01-15 · Modified
5.5EPSS 0.013
CVE-2017-17811
In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer overflow that will cause a remote denial of service attack, related to a strcpy in paste_tokens in asm/preproc.c, a similar issue to CVE-2017-11111.
Published 2017-12-21 · Modified
5.5EPSS 0.012
CVE-2018-1000667
NASM nasm-2.13.03 nasm- 2.14rc15 version 2.14rc15 and earlier contains a memory corruption (crashed) of nasm when handling a crafted file due to function assemble_file(inname, depend_ptr) at asm/nasm.c:482. vulnerability in function assemble_file(inname, depend_ptr) at asm/nasm.c:482. that can result in aborting/crash nasm program. This attack appear to be exploitable via a specially crafted asm file..
Published 2018-09-06 · Modified
5.5EPSS 0.012
CVE-2017-14228
In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in the function paste_tokens() in preproc.c, aka a NULL pointer dereference. It will lead to remote denial of service.
Published 2017-09-09 · Modified
5.5EPSS 0.012
CVE-2017-17816
In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in pp_getline in asm/preproc.c that will cause a remote denial of service attack.
Published 2017-12-21 · Modified
5.5EPSS 0.012
CVE-2017-17814
In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in do_directive in asm/preproc.c that will cause a remote denial of service attack.
Published 2017-12-21 · Modified
5.5EPSS 0.012
1 / 2Next →