Yasm Project
Yasm Project Yasm: vulnerabilidades y CVE
Yasm Project Yasm tiene 17 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-22653 | Media (4.8) | 0.25% | — | 29 may 2025 | yasm commit 9defefae was discovered to contain a NULL pointer dereference via the yasm_section_bcs_append function at section.c. |
| CVE-2023-49558 | Media (5.5) | 0.38% | — | 3 ene 2024 | An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_mmac_params function in the modules/preprocs/nasm/nasm-pp.c component. |
| CVE-2023-49557 | Media (5.5) | 0.43% | — | 3 ene 2024 | An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the yasm_section_bcs_first function in the libyasm/section.c component. |
| CVE-2023-49556 | Media (5.5) | 0.42% | — | 3 ene 2024 | Buffer Overflow vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expr_delete_term function in the libyasm/expr.c component. |
| CVE-2023-49555 | Media (5.5) | 0.38% | — | 3 ene 2024 | An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_smacro function in the modules/preprocs/nasm/nasm-pp.c component. |
| CVE-2023-49554 | Media (5.5) | 0.40% | — | 3 ene 2024 | Use After Free vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the do_directive function in the modules/preprocs/nasm/nasm-pp.c component. |
| CVE-2023-37732 | Media (5.5) | 0.37% | — | 26 jul 2023 | Yasm v1.3.0.78 was found prone to NULL Pointer Dereference in /libyasm/intnum.c and /elf/elf.c, which allows the attacker to cause a denial of service via a crafted file. |
| CVE-2023-31725 | Media (5.5) | 0.29% | — | 17 may 2023 | yasm 1.3.0.55.g101bc was discovered to contain a heap-use-after-free via the function expand_mmac_params at yasm/modules/preprocs/nasm/nasm-pp.c. |
| CVE-2023-31724 | Alta (7.8) | 0.33% | — | 17 may 2023 | yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the function do_directive at /nasm/nasm-pp.c. |
| CVE-2023-31723 | Media (5.5) | 0.29% | — | 17 may 2023 | yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the function expand_mmac_params at /nasm/nasm-pp.c. |
| CVE-2023-31975 | Baja (3.3) | 0.47% | — | 9 may 2023 | yasm v1.3.0 was discovered to contain a memory leak via the function yasm_intnum_copy at /libyasm/intnum.c. Note: Multiple third parties dispute this as a bug and not a vulnerability according to the YASM security… |
| CVE-2023-30402 | Media (5.5) | 0.29% | — | 25 abr 2023 | YASM v1.3.0 was discovered to contain a heap overflow via the function handle_dot_label at /nasm/nasm-token.re. Note: This has been disputed by third parties who argue this is a bug and not a security issue because yasm… |
| CVE-2023-29583 | Media (5.5) | 0.29% | — | 24 abr 2023 | yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr5 at /nasm/nasm-parse.c. Note: This has been disputed by third parties who argue this is a bug and not a security issue because… |
| CVE-2023-29582 | Media (5.5) | 0.34% | — | 24 abr 2023 | yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr1 at /nasm/nasm-parse.c. Note: This has been disputed by third parties who argue this is a bug and not a security issue because… |
| CVE-2023-29579 | Media (5.5) | 0.30% | — | 24 abr 2023 | yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the component yasm/yasm+0x43b466 in vsprintf. Note: This has been disputed by third parties who argue this is a bug and not a security issue because… |
| CVE-2023-29581 | Media (5.5) | 0.34% | — | 12 abr 2023 | yasm 1.3.0.55.g101bc has a segmentation violation in the function delete_Token at modules/preprocs/nasm/nasm-pp.c. NOTE: although a libyasm application could become unavailable if this were exploited, the vendor's… |
| CVE-2023-29580 | Media (5.5) | 0.31% | — | 12 abr 2023 | yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the component yasm_expr_create at /libyasm/expr.c. |