Yasm Project
Yasm Project Yasm: vulnerabilities and CVEs
Yasm Project Yasm has 17 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs17
Last 12 months0
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-22653 | Medium (4.8) | 0.25% | — | May 29, 2025 | yasm commit 9defefae was discovered to contain a NULL pointer dereference via the yasm_section_bcs_append function at section.c. |
| CVE-2023-49558 | Medium (5.5) | 0.38% | — | Jan 3, 2024 | An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_mmac_params function in the modules/preprocs/nasm/nasm-pp.c component. |
| CVE-2023-49557 | Medium (5.5) | 0.43% | — | Jan 3, 2024 | An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the yasm_section_bcs_first function in the libyasm/section.c component. |
| CVE-2023-49556 | Medium (5.5) | 0.42% | — | Jan 3, 2024 | Buffer Overflow vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expr_delete_term function in the libyasm/expr.c component. |
| CVE-2023-49555 | Medium (5.5) | 0.38% | — | Jan 3, 2024 | An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_smacro function in the modules/preprocs/nasm/nasm-pp.c component. |
| CVE-2023-49554 | Medium (5.5) | 0.40% | — | Jan 3, 2024 | Use After Free vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the do_directive function in the modules/preprocs/nasm/nasm-pp.c component. |
| CVE-2023-37732 | Medium (5.5) | 0.37% | — | Jul 26, 2023 | Yasm v1.3.0.78 was found prone to NULL Pointer Dereference in /libyasm/intnum.c and /elf/elf.c, which allows the attacker to cause a denial of service via a crafted file. |
| CVE-2023-31725 | Medium (5.5) | 0.29% | — | May 17, 2023 | yasm 1.3.0.55.g101bc was discovered to contain a heap-use-after-free via the function expand_mmac_params at yasm/modules/preprocs/nasm/nasm-pp.c. |
| CVE-2023-31724 | High (7.8) | 0.33% | — | May 17, 2023 | yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the function do_directive at /nasm/nasm-pp.c. |
| CVE-2023-31723 | Medium (5.5) | 0.29% | — | May 17, 2023 | yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the function expand_mmac_params at /nasm/nasm-pp.c. |
| CVE-2023-31975 | Low (3.3) | 0.47% | — | May 9, 2023 | yasm v1.3.0 was discovered to contain a memory leak via the function yasm_intnum_copy at /libyasm/intnum.c. Note: Multiple third parties dispute this as a bug and not a vulnerability according to the YASM security… |
| CVE-2023-30402 | Medium (5.5) | 0.29% | — | Apr 25, 2023 | YASM v1.3.0 was discovered to contain a heap overflow via the function handle_dot_label at /nasm/nasm-token.re. Note: This has been disputed by third parties who argue this is a bug and not a security issue because yasm… |
| CVE-2023-29583 | Medium (5.5) | 0.29% | — | Apr 24, 2023 | yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr5 at /nasm/nasm-parse.c. Note: This has been disputed by third parties who argue this is a bug and not a security issue because… |
| CVE-2023-29582 | Medium (5.5) | 0.34% | — | Apr 24, 2023 | yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr1 at /nasm/nasm-parse.c. Note: This has been disputed by third parties who argue this is a bug and not a security issue because… |
| CVE-2023-29579 | Medium (5.5) | 0.30% | — | Apr 24, 2023 | yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the component yasm/yasm+0x43b466 in vsprintf. Note: This has been disputed by third parties who argue this is a bug and not a security issue because… |
| CVE-2023-29581 | Medium (5.5) | 0.34% | — | Apr 12, 2023 | yasm 1.3.0.55.g101bc has a segmentation violation in the function delete_Token at modules/preprocs/nasm/nasm-pp.c. NOTE: although a libyasm application could become unavailable if this were exploited, the vendor's… |
| CVE-2023-29580 | Medium (5.5) | 0.31% | — | Apr 12, 2023 | yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the component yasm_expr_create at /libyasm/expr.c. |