Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.25% | — | Yasm Project Yasm | 29/5/2025 | 17/6/2026 | yasm commit 9defefae was discovered to contain a NULL pointer dereference via the yasm_section_bcs_append function at section.c. | |
| Modificada | Media (5.5) | 0.26% | — | Tortall Yasm | 18/1/2024 | 17/6/2026 | A memory leak issue discovered in YASM v.1.3.0 allows a local attacker to cause a denial of service via the new_Token function in the modules/preprocs/nasm/nasm-pp:1512. | |
| Modificada | Media (5.5) | 0.38% | — | Yasm Project Yasm | 3/1/2024 | 17/6/2026 | An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_mmac_params function in the modules/preprocs/nasm/nasm-pp.c component. | |
| Modificada | Media (5.5) | 0.43% | — | Yasm Project Yasm | 3/1/2024 | 17/6/2026 | An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the yasm_section_bcs_first function in the libyasm/section.c component. | |
| Modificada | Media (5.5) | 0.42% | — | Yasm Project Yasm | 3/1/2024 | 17/6/2026 | Buffer Overflow vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expr_delete_term function in the libyasm/expr.c component. | |
| Modificada | Media (5.5) | 0.38% | — | Yasm Project Yasm | 3/1/2024 | 17/6/2026 | An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_smacro function in the modules/preprocs/nasm/nasm-pp.c component. | |
| Modificada | Media (5.5) | 0.40% | — | Yasm Project Yasm | 3/1/2024 | 17/6/2026 | Use After Free vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the do_directive function in the modules/preprocs/nasm/nasm-pp.c component. | |
| Modificada | Media (5.5) | 0.37% | — | Yasm Project Yasm | 26/7/2023 | 17/6/2026 | Yasm v1.3.0.78 was found prone to NULL Pointer Dereference in /libyasm/intnum.c and /elf/elf.c, which allows the attacker to cause a denial of service via a crafted file. | |
| Modificada | Media (5.5) | 0.29% | — | Yasm Project Yasm | 17/5/2023 | 17/6/2026 | yasm 1.3.0.55.g101bc was discovered to contain a heap-use-after-free via the function expand_mmac_params at yasm/modules/preprocs/nasm/nasm-pp.c. | |
| Modificada | Alta (7.8) | 0.33% | — | Yasm Project Yasm | 17/5/2023 | 17/6/2026 | yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the function do_directive at /nasm/nasm-pp.c. | |
| Modificada | Media (5.5) | 0.29% | — | Yasm Project Yasm | 17/5/2023 | 17/6/2026 | yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the function expand_mmac_params at /nasm/nasm-pp.c. | |
| Modificada | Media (5.5) | 0.31% | — | Tortall Yasm | 9/5/2023 | 17/6/2026 | yasm v1.3.0 was discovered to contain a use after free via the function expand_mmac_params at /nasm/nasm-pp.c. Note: Multiple third parties dispute this as a bug and not a vulnerability according to the YASM security policy. | |
| Modificada | Baja (3.3) | 0.47% | — | Yasm Project Yasm | 9/5/2023 | 17/6/2026 | yasm v1.3.0 was discovered to contain a memory leak via the function yasm_intnum_copy at /libyasm/intnum.c. Note: Multiple third parties dispute this as a bug and not a vulnerability according to the YASM security policy. | |
| Modificada | Media (5.5) | 0.29% | — | Tortall Yasm | 9/5/2023 | 17/6/2026 | yasm v1.3.0 was discovered to contain a use after free via the function error at /nasm/nasm-pp.c. Note: Multiple third parties dispute this as a bug and not a vulnerability according to the YASM security policy. | |
| Modificada | Media (5.5) | 0.29% | — | Tortall Yasm | 9/5/2023 | 17/6/2026 | yasm v1.3.0 was discovered to contain a use after free via the function pp_getline at /nasm/nasm-pp.c. Note: Multiple third parties dispute this as a bug and not a vulnerability according to the YASM security policy. | |
| Modificada | Media (5.5) | 0.29% | — | Yasm Project Yasm | 25/4/2023 | 17/6/2026 | YASM v1.3.0 was discovered to contain a heap overflow via the function handle_dot_label at /nasm/nasm-token.re. Note: This has been disputed by third parties who argue this is a bug and not a security issue because yasm is a standalone program not designed to run untrusted code. | |
| Modificada | Media (5.5) | 0.29% | — | Yasm Project Yasm | 24/4/2023 | 17/6/2026 | yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr5 at /nasm/nasm-parse.c. Note: This has been disputed by third parties who argue this is a bug and not a security issue because yasm is a standalone program not designed to run untrusted code. | |
| Modificada | Media (5.5) | 0.34% | — | Yasm Project Yasm | 24/4/2023 | 17/6/2026 | yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr1 at /nasm/nasm-parse.c. Note: This has been disputed by third parties who argue this is a bug and not a security issue because yasm is a standalone program not designed to run untrusted code. | |
| Modificada | Media (5.5) | 0.30% | — | Yasm Project Yasm | 24/4/2023 | 17/6/2026 | yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the component yasm/yasm+0x43b466 in vsprintf. Note: This has been disputed by third parties who argue this is a bug and not a security issue because yasm is a standalone program not designed to run untrusted code. | |
| Modificada | Media (5.5) | 0.34% | — | Yasm Project Yasm | 12/4/2023 | 17/6/2026 | yasm 1.3.0.55.g101bc has a segmentation violation in the function delete_Token at modules/preprocs/nasm/nasm-pp.c. NOTE: although a libyasm application could become unavailable if this were exploited, the vendor's position is that there is no security relevance because there is either supposed to be input validation… | |
| Modificada | Media (5.5) | 0.31% | — | Yasm Project Yasm | 12/4/2023 | 17/6/2026 | yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the component yasm_expr_create at /libyasm/expr.c. | |
| Modificada | Media (5.5) | 0.33% | — | Tortall Yasm | 26/7/2022 | 17/6/2026 | An issue was discovered in yasm version 1.3.0. There is a use-after-free in error() in modules/preprocs/nasm/nasm-pp.c. | |
| Modificada | Media (5.5) | 0.33% | — | Tortall Yasm | 26/7/2022 | 17/6/2026 | An issue was discovered in yasm version 1.3.0. There is a use-after-free in pp_getline() in modules/preprocs/nasm/nasm-pp.c. | |
| Modificada | Media (5.5) | 0.33% | — | Tortall Yasm | 26/7/2022 | 17/6/2026 | An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in expand_smacro() in modules/preprocs/nasm/nasm-pp.c. | |
| Modificada | Media (5.5) | 0.33% | — | Tortall Yasm | 26/7/2022 | 17/6/2026 | An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in expand_mmacro() in modules/preprocs/nasm/nasm-pp.c. |