VendorsNASMnetwide_assemblerall versions
Vulnerabilities

NASM Netwide Assembler

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

75CVEs
CVE-2017-17813
In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in the pp_list_one_macro function in asm/preproc.c that will cause a remote denial of service attack, related to mishandling of line-syntax errors.
Published 2017-12-21 · Modified
5.5EPSS 0.012
CVE-2018-16999
Netwide Assembler (NASM) 2.14rc15 has an invalid memory write (segmentation fault) in expand_smacro in preproc.c, which allows attackers to cause a denial of service via a crafted input file.
Published 2018-09-13 · Modified
5.5EPSS 0.011
CVE-2018-10316
Netwide Assembler (NASM) 2.14rc0 has an endless while loop in the assemble_file function of asm/nasm.c because of a globallineno integer overflow.
Published 2018-04-24 · Modified
5.5EPSS 0.011
CVE-2018-10016
Netwide Assembler (NASM) 2.14rc0 has a division-by-zero vulnerability in the expr5 function in asm/eval.c via a malformed input file.
Published 2018-04-11 · Modified
5.5EPSS 0.011
CVE-2018-19755
There is an illegal address access at asm/preproc.c (function: is_mmacro) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service (out-of-bounds array access) because a certain conversion can result in a negative integer.
Published 2018-11-30 · Modified
5.5EPSS 0.010
CVE-2018-16382
Netwide Assembler (NASM) 2.14rc15 has a buffer over-read in x86/regflags.c.
Published 2018-09-03 · Modified
5.5EPSS 0.010
CVE-2019-14248
In libnasm.a in Netwide Assembler (NASM) 2.14.xx, asm/pragma.c allows a NULL pointer dereference in process_pragma, search_pragma_list, and nasm_set_limit when "%pragma limit" is mishandled.
Published 2019-07-24 · Modified
5.5EPSS 0.009
CVE-2018-20535
There is a use-after-free at asm/preproc.c (function pp_getline) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service during a line-number increment attempt.
Published 2018-12-28 · Modified
5.5EPSS 0.008
CVE-2018-20538
There is a use-after-free at asm/preproc.c (function pp_getline) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service during certain finishes tests.
Published 2018-12-28 · Modified
5.5EPSS 0.008
CVE-2020-24241
In Netwide Assembler (NASM) 2.15rc10, there is heap use-after-free in saa_wbytes in nasmlib/saa.c.
Published 2020-08-25 · Modified
5.5EPSS 0.008
CVE-2018-19209
Netwide Assembler (NASM) 2.14rc15 has a NULL pointer dereference in the function find_label in asm/labels.c that will lead to a DoS attack.
Published 2018-11-12 · Modified
5.5EPSS 0.008
CVE-2019-20334
In Netwide Assembler (NASM) 2.14.02, stack consumption occurs in expr# functions in asm/eval.c. This potentially affects the relationships among expr0, expr1, expr2, expr3, expr4, expr5, and expr6 (and stdscan in asm/stdscan.c). This is similar to CVE-2019-6290 and CVE-2019-6291.
Published 2020-01-04 · Modified
5.5EPSS 0.008
CVE-2018-1000886
nasm version 2.14.01rc5, 2.15 contains a Buffer Overflow vulnerability in asm/stdscan.c:130 that can result in Stack-overflow caused by triggering endless macro generation, crash the program. This attack appear to be exploitable via a crafted nasm input file.
Published 2018-12-20 · Modified
5.5EPSS 0.008
CVE-2018-19213
Netwide Assembler (NASM) through 2.14rc16 has memory leaks that may lead to DoS, related to nasm_malloc in nasmlib/malloc.c.
Published 2018-11-12 · Modified
5.5EPSS 0.008
CVE-2019-7147
A buffer over-read exists in the function crc64ib in crc64.c in nasmlib in Netwide Assembler (NASM) 2.14rc16. A crafted asm input can cause segmentation faults, leading to denial-of-service.
Published 2019-01-29 · Modified
5.5EPSS 0.007
CVE-2020-24242
In Netwide Assembler (NASM) 2.15rc10, SEGV can be triggered in tok_text in asm/preproc.c by accessing READ memory.
Published 2020-08-25 · Modified
5.5EPSS 0.007
CVE-2021-45257
An infinite loop vulnerability exists in nasm 2.16rc0 via the gpaste_tokens function.
Published 2021-12-22 · Modified
5.5EPSS 0.007
CVE-2021-45256
A Null Pointer Dereference vulnerability existfs in nasm 2.16rc0 via asm/preproc.c.
Published 2021-12-22 · Modified
5.5EPSS 0.006
CVE-2020-21528
A Segmentation Fault issue discovered in in ieee_segment function in outieee.c in nasm 2.14.03 and 2.15 allows remote attackers to cause a denial of service via crafted assembly file.
Published 2023-08-22 · Modified
5.5EPSS 0.005
CVE-2022-29654
Buffer overflow vulnerability in quote_for_pmake in asm/nasm.c in nasm before 2.15.05 allows attackers to cause a denial of service via crafted file.
Published 2023-08-22 · Modified
5.5EPSS 0.005
CVE-2020-21687
Buffer Overflow vulnerability in scan function in stdscan.c in nasm 2.15rc0 allows remote attackers to cause a denial of service via crafted asm file.
Published 2023-08-22 · Modified
5.5EPSS 0.004
CVE-2020-21685
Buffer Overflow vulnerability in hash_findi function in hashtbl.c in nasm 2.15rc0 allows remote attackers to cause a denial of service via crafted asm file.
Published 2023-08-22 · Modified
5.5EPSS 0.004
CVE-2020-21686
A stack-use-after-scope issue discovered in expand_mmac_params function in preproc.c in nasm before 2.15.04 allows remote attackers to cause a denial of service via crafted asm file.
Published 2023-08-22 · Modified
5.5EPSS 0.004
CVE-2022-46457
NASM v2.16 was discovered to contain a segmentation violation in the component ieee_write_file at /output/outieee.c.
Published 2023-01-04 · Modified
5.5EPSS 0.003
CVE-2021-33450
An issue was discovered in NASM version 2.16rc0. There are memory leaks in nasm_calloc() in nasmlib/alloc.c.
Published 2022-07-26 · Modified
5.5EPSS 0.003
CVE-2021-33452
An issue was discovered in NASM version 2.16rc0. There are memory leaks in nasm_malloc() in nasmlib/alloc.c.
Published 2022-07-26 · Modified
5.5EPSS 0.003
CVE-2022-44368
NASM v2.16 was discovered to contain a null pointer deference in the NASM component
Published 2023-03-29 · Modified
5.5EPSS 0.003
CVE-2022-44369
NASM 2.16 (development) is vulnerable to 476: Null Pointer Dereference via output/outaout.c.
Published 2023-03-29 · Modified
5.5EPSS 0.003
CVE-2023-38665
Null pointer dereference in ieee_write_file in nasm 2.16rc0 allows attackers to cause a denial of service (crash).
Published 2023-08-22 · Modified
5.5EPSS 0.003
CVE-2022-41420
nasm v2.16 was discovered to contain a stack overflow in the Ndisasm component
Published 2022-10-03 · Modified
5.5EPSS 0.003
CVE-2020-18780
A Use After Free vulnerability in function new_Token in asm/preproc.c in nasm 2.14.02 allows attackers to cause a denial of service via crafted nasm command.
Published 2023-08-22 · Modified
5.5EPSS 0.003
CVE-2023-38667
Stack-based buffer over-read in function disasm in nasm 2.16 allows attackers to cause a denial of service.
Published 2023-08-22 · Modified
5.5EPSS 0.003
CVE-2023-38668
Stack-based buffer over-read in disasm in nasm 2.16 allows attackers to cause a denial of service (crash).
Published 2023-08-22 · Modified
5.5EPSS 0.003
CVE-2025-8844
NASM Netwide Assember preproc.c parse_smacro_template null pointer dereference
Published 2025-08-11 · Analyzed
5.5EPSS 0.003
CVE-2020-18974
Buffer Overflow in Netwide Assembler (NASM) v2.15.xx allows attackers to cause a denial of service via 'crc64i' in the component 'nasmlib/crc64'. This issue is different than CVE-2019-7147.
Published 2021-08-25 · Modified
4.3EPSS 0.008
← Prev2 / 2