Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
75 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.33% | — | Nasm Netwide Assembler | 26/7/2022 | 17/6/2026 | An issue was discovered in NASM version 2.16rc0. There are memory leaks in nasm_calloc() in nasmlib/alloc.c. | |
| Modificada | Media (5.5) | 0.67% | — | Nasm Netwide Assembler | 22/12/2021 | 17/6/2026 | An infinite loop vulnerability exists in nasm 2.16rc0 via the gpaste_tokens function. | |
| Modificada | Media (5.5) | 0.67% | — | Nasm Netwide Assembler | 22/12/2021 | 17/6/2026 | A Null Pointer Dereference vulnerability existfs in nasm 2.16rc0 via asm/preproc.c. | |
| Modificada | Baja (3.3) | 0.83% | — | Nasm Netwide Assembler | 25/8/2021 | 17/6/2026 | Buffer Overflow in Netwide Assembler (NASM) v2.15.xx allows attackers to cause a denial of service via 'crc64i' in the component 'nasmlib/crc64'. This issue is different than CVE-2019-7147. | |
| Modificada | Crítica (9.8) | 1.4% | — | Nasm Netwide Assembler | 4/9/2020 | 17/6/2026 | In NASM 2.15.04rc3, there is a double-free vulnerability in pp_tokline asm/preproc.c. This is fixed in commit 8806c3ca007b84accac21dd88b900fb03614ceb7. | |
| Modificada | Media (5.5) | 0.74% | — | Nasm Netwide Assembler | 25/8/2020 | 17/6/2026 | In Netwide Assembler (NASM) 2.15rc10, SEGV can be triggered in tok_text in asm/preproc.c by accessing READ memory. | |
| Modificada | Media (5.5) | 0.78% | — | Nasm Netwide Assembler | 25/8/2020 | 17/6/2026 | In Netwide Assembler (NASM) 2.15rc10, there is heap use-after-free in saa_wbytes in nasmlib/saa.c. | |
| Modificada | Alta (7.1) | 0.84% | — | Nasm Netwide Assembler | 6/1/2020 | 17/6/2026 | In Netwide Assembler (NASM) 2.15rc0, a heap-based buffer over-read occurs (via a crafted .asm file) in set_text_free when called from expand_one_smacro in asm/preproc.c. | |
| Modificada | Media (5.5) | 0.76% | — | Nasm Netwide Assembler | 4/1/2020 | 17/6/2026 | In Netwide Assembler (NASM) 2.14.02, stack consumption occurs in expr# functions in asm/eval.c. This potentially affects the relationships among expr0, expr1, expr2, expr3, expr4, expr5, and expr6 (and stdscan in asm/stdscan.c). This is similar to CVE-2019-6290 and CVE-2019-6291. | |
| Modificada | Media (5.5) | 0.92% | — | Nasm Netwide Assembler | 24/7/2019 | 17/6/2026 | In libnasm.a in Netwide Assembler (NASM) 2.14.xx, asm/pragma.c allows a NULL pointer dereference in process_pragma, search_pragma_list, and nasm_set_limit when "%pragma limit" is mishandled. | |
| Modificada | Alta (7.8) | 1.1% | — | Nasm Netwide Assembler | 15/2/2019 | 17/6/2026 | In Netwide Assembler (NASM) 2.14.02, there is a use-after-free in paste_tokens in asm/preproc.c. | |
| Modificada | Media (5.5) | 0.75% | — | Nasm Netwide Assembler | 29/1/2019 | 17/6/2026 | A buffer over-read exists in the function crc64ib in crc64.c in nasmlib in Netwide Assembler (NASM) 2.14rc16. A crafted asm input can cause segmentation faults, leading to denial-of-service. | |
| Modificada | Media (5.5) | 1.3% | — | Nasm Netwide Assembler | 15/1/2019 | 17/6/2026 | An issue was discovered in the function expr6 in eval.c in Netwide Assembler (NASM) through 2.14.02. There is a stack exhaustion problem caused by the expr6 function making recursive calls to itself in certain scenarios involving lots of '!' or '+' or '-' characters. Remote attackers could leverage this vulnerability… | |
| Modificada | Media (5.5) | 1.3% | — | Nasm Netwide Assembler | 15/1/2019 | 17/6/2026 | An infinite recursion issue was discovered in eval.c in Netwide Assembler (NASM) through 2.14.02. There is a stack exhaustion problem resulting from infinite recursion in the functions expr, rexp, bexpr and cexpr in certain scenarios involving lots of '{' characters. Remote attackers could leverage this vulnerability… | |
| Modificada | Media (5.5) | 0.79% | — | Nasm Netwide Assembler | 28/12/2018 | 17/6/2026 | There is a use-after-free at asm/preproc.c (function pp_getline) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service during certain finishes tests. | |
| Modificada | Media (5.5) | 0.80% | — | Nasm Netwide Assembler | 28/12/2018 | 17/6/2026 | There is a use-after-free at asm/preproc.c (function pp_getline) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service during a line-number increment attempt. | |
| Modificada | Media (5.5) | 0.75% | — | Nasm Netwide Assembler | 20/12/2018 | 17/6/2026 | nasm version 2.14.01rc5, 2.15 contains a Buffer Overflow vulnerability in asm/stdscan.c:130 that can result in Stack-overflow caused by triggering endless macro generation, crash the program. This attack appear to be exploitable via a crafted nasm input file. | |
| Modificada | Media (5.5) | 1.00% | — | Nasm Netwide Assembler | 30/11/2018 | 17/6/2026 | There is an illegal address access at asm/preproc.c (function: is_mmacro) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service (out-of-bounds array access) because a certain conversion can result in a negative integer. | |
| Modificada | Alta (7.8) | 1.3% | — | Nasm Netwide AssemblerDebian Linux | 12/11/2018 | 17/6/2026 | Netwide Assembler (NASM) before 2.13.02 has a use-after-free in detoken at asm/preproc.c. | |
| Modificada | Alta (7.8) | 1.2% | — | Nasm Netwide AssemblerRedhat Enterprise Linux | 12/11/2018 | 17/6/2026 | Netwide Assembler (NASM) 2.14rc16 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for the special cases of the % and $ and ! characters. | |
| Modificada | Alta (7.8) | 1.3% | — | Nasm Netwide AssemblerRedhat Enterprise Linux | 12/11/2018 | 17/6/2026 | Netwide Assembler (NASM) 2.14rc15 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for insufficient input. | |
| Modificada | Media (5.5) | 0.75% | — | Nasm Netwide Assembler | 12/11/2018 | 17/6/2026 | Netwide Assembler (NASM) through 2.14rc16 has memory leaks that may lead to DoS, related to nasm_malloc in nasmlib/malloc.c. | |
| Modificada | Media (5.5) | 0.78% | — | Nasm Netwide Assembler | 12/11/2018 | 17/6/2026 | Netwide Assembler (NASM) 2.14rc15 has a NULL pointer dereference in the function find_label in asm/labels.c that will lead to a DoS attack. | |
| Modificada | Media (5.5) | 1.1% | — | Nasm Netwide Assembler | 13/9/2018 | 17/6/2026 | Netwide Assembler (NASM) 2.14rc15 has an invalid memory write (segmentation fault) in expand_smacro in preproc.c, which allows attackers to cause a denial of service via a crafted input file. | |
| Modificada | Media (5.5) | 5.2% | — | Nasm Netwide Assembler | 6/9/2018 | 17/6/2026 | asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a denial of service via a crafted file. |