Nasm
Nasm Netwide Assembler: vulnerabilidades y CVE
Nasm Netwide Assembler tiene 75 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE75
Últimos 12 meses3
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-6069 | Alta (7.5) | 0.46% | — | 10 abr 2026 | NASM’s disasm() function contains a stack based buffer overflow when formatting disassembly output, allowing an attacker triggered out-of-bounds write when `slen` exceeds the buffer capacity. |
| CVE-2026-6068 | Crítica (9.6) | 0.48% | — | 10 abr 2026 | NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the global depend_file and later dereferenced, as the response-file buffer is… |
| CVE-2026-6067 | Media (5.5) | 0.36% | — | 10 abr 2026 | A heap buffer overflow vulnerability exists in the Netwide Assembler (NASM) due to a lack of bounds checking in the obj_directive() function. This vulnerability can be exploited by a user assembling a malicious .asm… |
| CVE-2025-8846 | Baja (1.9) | 0.28% | — | 11 ago 2025 | A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected is the function parse_line of the file parser.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached… |
| CVE-2025-8845 | Baja (1.9) | 0.28% | — | 11 ago 2025 | A vulnerability was identified in NASM Netwide Assember 2.17rc0. This issue affects the function assemble_file of the file nasm.c. The manipulation leads to stack-based buffer overflow. It is possible to launch the… |
| CVE-2025-8844 | Baja (1.9) | 0.26% | — | 11 ago 2025 | A vulnerability was determined in NASM Netwide Assember 2.17rc0. This vulnerability affects the function parse_smacro_template of the file preproc.c. The manipulation leads to null pointer dereference. Attacking locally… |
| CVE-2025-8843 | Baja (1.9) | 0.26% | — | 11 ago 2025 | A vulnerability was found in NASM Netwide Assember 2.17rc0. This affects the function macho_no_dead_strip of the file outmacho.c. The manipulation leads to heap-based buffer overflow. Local access is required to… |
| CVE-2025-8842 | Baja (1.9) | 0.23% | — | 11 ago 2025 | A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected by this issue is the function do_directive of the file preproc.c. The manipulation leads to use after free. An attack has to be approached… |
| CVE-2023-38668 | Media (5.5) | 0.29% | — | 22 ago 2023 | Stack-based buffer over-read in disasm in nasm 2.16 allows attackers to cause a denial of service (crash). |
| CVE-2023-38667 | Media (5.5) | 0.29% | — | 22 ago 2023 | Stack-based buffer over-read in function disasm in nasm 2.16 allows attackers to cause a denial of service. |
| CVE-2023-38665 | Media (5.5) | 0.31% | — | 22 ago 2023 | Null pointer dereference in ieee_write_file in nasm 2.16rc0 allows attackers to cause a denial of service (crash). |
| CVE-2022-29654 | Media (5.5) | 0.47% | — | 22 ago 2023 | Buffer overflow vulnerability in quote_for_pmake in asm/nasm.c in nasm before 2.15.05 allows attackers to cause a denial of service via crafted file. |
| CVE-2020-21687 | Media (5.5) | 0.44% | — | 22 ago 2023 | Buffer Overflow vulnerability in scan function in stdscan.c in nasm 2.15rc0 allows remote attackers to cause a denial of service via crafted asm file. |
| CVE-2020-21686 | Media (5.5) | 0.44% | — | 22 ago 2023 | A stack-use-after-scope issue discovered in expand_mmac_params function in preproc.c in nasm before 2.15.04 allows remote attackers to cause a denial of service via crafted asm file. |
| CVE-2020-21685 | Media (5.5) | 0.44% | — | 22 ago 2023 | Buffer Overflow vulnerability in hash_findi function in hashtbl.c in nasm 2.15rc0 allows remote attackers to cause a denial of service via crafted asm file. |
| CVE-2020-21528 | Media (5.5) | 0.54% | — | 22 ago 2023 | A Segmentation Fault issue discovered in in ieee_segment function in outieee.c in nasm 2.14.03 and 2.15 allows remote attackers to cause a denial of service via crafted assembly file. |
| CVE-2020-18780 | Media (5.5) | 0.29% | — | 22 ago 2023 | A Use After Free vulnerability in function new_Token in asm/preproc.c in nasm 2.14.02 allows attackers to cause a denial of service via crafted nasm command. |
| CVE-2023-31722 | Alta (7.8) | 0.35% | — | 17 may 2023 | There exists a heap buffer overflow in nasm 2.16.02rc1 (GitHub commit: b952891). |
| CVE-2022-44370 | Alta (7.8) | 0.45% | — | 29 mar 2023 | NASM v2.16 was discovered to contain a heap buffer overflow in the component quote_for_pmake() asm/nasm.c:856 |
| CVE-2022-44369 | Media (5.5) | 0.31% | — | 29 mar 2023 | NASM 2.16 (development) is vulnerable to 476: Null Pointer Dereference via output/outaout.c. |
| CVE-2022-44368 | Media (5.5) | 0.31% | — | 29 mar 2023 | NASM v2.16 was discovered to contain a null pointer deference in the NASM component |
| CVE-2022-46457 | Media (5.5) | 0.34% | — | 4 ene 2023 | NASM v2.16 was discovered to contain a segmentation violation in the component ieee_write_file at /output/outieee.c. |
| CVE-2022-46456 | Media (6.1) | 0.36% | — | 4 ene 2023 | NASM v2.16 was discovered to contain a global buffer overflow in the component dbgdbg_typevalue at /output/outdbg.c. |
| CVE-2022-41420 | Media (5.5) | 0.32% | — | 3 oct 2022 | nasm v2.16 was discovered to contain a stack overflow in the Ndisasm component |
| CVE-2021-33452 | Media (5.5) | 0.33% | — | 26 jul 2022 | An issue was discovered in NASM version 2.16rc0. There are memory leaks in nasm_malloc() in nasmlib/alloc.c. |
| CVE-2021-33450 | Media (5.5) | 0.33% | — | 26 jul 2022 | An issue was discovered in NASM version 2.16rc0. There are memory leaks in nasm_calloc() in nasmlib/alloc.c. |
| CVE-2021-45257 | Media (5.5) | 0.67% | — | 22 dic 2021 | An infinite loop vulnerability exists in nasm 2.16rc0 via the gpaste_tokens function. |
| CVE-2021-45256 | Media (5.5) | 0.61% | — | 22 dic 2021 | A Null Pointer Dereference vulnerability existfs in nasm 2.16rc0 via asm/preproc.c. |
| CVE-2020-18974 | Baja (3.3) | 0.83% | — | 25 ago 2021 | Buffer Overflow in Netwide Assembler (NASM) v2.15.xx allows attackers to cause a denial of service via 'crc64i' in the component 'nasmlib/crc64'. This issue is different than CVE-2019-7147. |
| CVE-2020-24978 | Crítica (9.8) | 1.4% | — | 4 sept 2020 | In NASM 2.15.04rc3, there is a double-free vulnerability in pp_tokline asm/preproc.c. This is fixed in commit 8806c3ca007b84accac21dd88b900fb03614ceb7. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.