Debian Nasm vulnerabilities
46 known vulnerabilities affecting debian/nasm.
Total CVEs
46
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH6MEDIUM11LOW26
Vulnerabilities
Page 1 of 3
CVE-2004-1287P3CRITICALCVSS 10.0PoCfixed in nasm 0.98.38-1.1 (bookworm)2004
CVE-2004-1287 [CRITICAL] CVE-2004-1287: nasm - Buffer overflow in the error function in preproc.c for NASM 0.98.38 1.2 allows a...
Buffer overflow in the error function in preproc.c for NASM 0.98.38 1.2 allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2005-1194.
Scope: local
bookworm: resolved (fixed in 0.98.38-1.1)
bullseye: resolved (fixed in 0.98.38-1.1)
forky: resolved (fixed in 0.98.38-1.1)
sid: resolved (fixed in 0.98.38-1.1)
trixie: res
debian
CVE-2008-2719P3LOWCVSS 6.8PoCfixed in nasm 2.03.01-1 (bookworm)2008
CVE-2008-2719 [MEDIUM] CVE-2008-2719: nasm - Off-by-one error in the ppscan function (preproc.c) in Netwide Assembler (NASM) ...
Off-by-one error in the ppscan function (preproc.c) in Netwide Assembler (NASM) 2.02 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted file that triggers a stack-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 2.03.01-1)
bullseye: resolved (fixed in 2.03.01-1)
forky: resolved (fixe
debian
CVE-2018-16517P4LOWCVSS 5.5PoCfixed in nasm 2.14-1 (bookworm)2018
CVE-2018-16517 [MEDIUM] CVE-2018-16517: nasm - asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, w...
asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a denial of service via a crafted file.
Scope: local
bookworm: resolved (fixed in 2.14-1)
bullseye: resolved (fixed in 2.14-1)
forky: resolved (fixed in 2.14-1)
sid: resolved (fixed in 2.14-1)
trixie: resolved (fixed in 2.14-1)
debian
CVE-2017-10686P3HIGHCVSS 7.8fixed in nasm 2.13.02-0.1 (bookworm)2017
CVE-2017-10686 [HIGH] CVE-2017-10686: nasm - In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vuln...
In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vulnerabilities in the tool nasm. The related heap is allocated in the token() function and freed in the detoken() function (called by pp_getline()) - it is used again at multiple positions later that could cause multiple damages. For example, it causes a corrupted double-linked list in detoken
debian
CVE-2020-24978P3CRITICALCVSS 9.8fixed in nasm 2.15.04-1 (bookworm)2020
CVE-2020-24978 [CRITICAL] CVE-2020-24978: nasm - In NASM 2.15.04rc3, there is a double-free vulnerability in pp_tokline asm/prepr...
In NASM 2.15.04rc3, there is a double-free vulnerability in pp_tokline asm/preproc.c. This is fixed in commit 8806c3ca007b84accac21dd88b900fb03614ceb7.
Scope: local
bookworm: resolved (fixed in 2.15.04-1)
bullseye: resolved (fixed in 2.15.04-1)
forky: resolved (fixed in 2.15.04-1)
sid: resolved (fixed in 2.15.04-1)
trixie: resolved (fixed in 2.15.04-1)
debian
CVE-2017-17818P3HIGHCVSS 7.5fixed in nasm 2.13.02-0.1 (bookworm)2017
CVE-2017-17818 [HIGH] CVE-2017-17818: nasm - In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer over-read that...
In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer over-read that will cause a remote denial of service attack, related to a while loop in paste_tokens in asm/preproc.c.
Scope: local
bookworm: resolved (fixed in 2.13.02-0.1)
bullseye: resolved (fixed in 2.13.02-0.1)
forky: resolved (fixed in 2.13.02-0.1)
sid: resolved (fixed in 2.13.02-0.1)
trixie: resol
debian
CVE-2008-7177P3LOWCVSS 6.8fixed in nasm 2.03.01-1 (bookworm)2008
CVE-2008-7177 [MEDIUM] CVE-2008-7177: nasm - Buffer overflow in the listing module in Netwide Assembler (NASM) before 2.03.01...
Buffer overflow in the listing module in Netwide Assembler (NASM) before 2.03.01 has unknown impact and attack vectors, a different vulnerability than CVE-2008-2719.
Scope: local
bookworm: resolved (fixed in 2.03.01-1)
bullseye: resolved (fixed in 2.03.01-1)
forky: resolved (fixed in 2.03.01-1)
sid: resolved (fixed in 2.03.01-1)
trixie: resolved (fixed in 2.03.01-1)
debian
CVE-2018-19216P4HIGHCVSS 7.8fixed in nasm 2.13.02-0.1 (bookworm)2018
CVE-2018-19216 [HIGH] CVE-2018-19216: nasm - Netwide Assembler (NASM) before 2.13.02 has a use-after-free in detoken at asm/p...
Netwide Assembler (NASM) before 2.13.02 has a use-after-free in detoken at asm/preproc.c.
Scope: local
bookworm: resolved (fixed in 2.13.02-0.1)
bullseye: resolved (fixed in 2.13.02-0.1)
forky: resolved (fixed in 2.13.02-0.1)
sid: resolved (fixed in 2.13.02-0.1)
trixie: resolved (fixed in 2.13.02-0.1)
debian
CVE-2022-44370P4LOWCVSS 7.8fixed in nasm 2.16.01-1 (bookworm)2022
CVE-2022-44370 [HIGH] CVE-2022-44370: nasm - NASM v2.16 was discovered to contain a heap buffer overflow in the component quo...
NASM v2.16 was discovered to contain a heap buffer overflow in the component quote_for_pmake() asm/nasm.c:856
Scope: local
bookworm: resolved (fixed in 2.16.01-1)
bullseye: open
forky: resolved (fixed in 2.16.01-1)
sid: resolved (fixed in 2.16.01-1)
trixie: resolved (fixed in 2.16.01-1)
debian
CVE-2018-8883P4LOWCVSS 7.8fixed in nasm 2.14-1 (bookworm)2018
CVE-2018-8883 [HIGH] CVE-2018-8883: nasm - Netwide Assembler (NASM) 2.13.02rc2 has a buffer over-read in the parse_line fun...
Netwide Assembler (NASM) 2.13.02rc2 has a buffer over-read in the parse_line function in asm/parser.c via uncontrolled access to nasm_reg_flags.
Scope: local
bookworm: resolved (fixed in 2.14-1)
bullseye: resolved (fixed in 2.14-1)
forky: resolved (fixed in 2.14-1)
sid: resolved (fixed in 2.14-1)
trixie: resolved (fixed in 2.14-1)
debian
CVE-2017-11111P4HIGHCVSS 7.8fixed in nasm 2.13.02-0.1 (bookworm)2017
CVE-2017-11111 [HIGH] CVE-2017-11111: nasm - In Netwide Assembler (NASM) 2.14rc0, preproc.c allows remote attackers to cause ...
In Netwide Assembler (NASM) 2.14rc0, preproc.c allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.
Scope: local
bookworm: resolved (fixed in 2.13.02-0.1)
bullseye: resolved (fixed in 2.13.02-0.1)
forky: resolved (fixed in 2.13.02-0.1)
sid: resolved (fixed i
debian
CVE-2018-19214P4LOWCVSS 7.8fixed in nasm 2.14-1 (bookworm)2018
CVE-2018-19214 [HIGH] CVE-2018-19214: nasm - Netwide Assembler (NASM) 2.14rc15 has a heap-based buffer over-read in expand_mm...
Netwide Assembler (NASM) 2.14rc15 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for insufficient input.
Scope: local
bookworm: resolved (fixed in 2.14-1)
bullseye: resolved (fixed in 2.14-1)
forky: resolved (fixed in 2.14-1)
sid: resolved (fixed in 2.14-1)
trixie: resolved (fixed in 2.14-1)
debian
CVE-2018-8882P4LOWCVSS 7.8fixed in nasm 2.14-1 (bookworm)2018
CVE-2018-8882 [HIGH] CVE-2018-8882: nasm - Netwide Assembler (NASM) 2.13.02rc2 has a stack-based buffer under-read in the f...
Netwide Assembler (NASM) 2.13.02rc2 has a stack-based buffer under-read in the function ieee_shr in asm/float.c via a large shift value.
Scope: local
bookworm: resolved (fixed in 2.14-1)
bullseye: resolved (fixed in 2.14-1)
forky: resolved (fixed in 2.14-1)
sid: resolved (fixed in 2.14-1)
trixie: resolved (fixed in 2.14-1)
debian
CVE-2018-10254P4HIGHCVSS 7.8fixed in nasm 2.14-1 (bookworm)2018
CVE-2018-10254 [HIGH] CVE-2018-10254: nasm - Netwide Assembler (NASM) 2.13 has a stack-based buffer over-read in the disasm f...
Netwide Assembler (NASM) 2.13 has a stack-based buffer over-read in the disasm function of the disasm/disasm.c file. Remote attackers could leverage this vulnerability to cause a denial of service or possibly have unspecified other impact via a crafted ELF file.
Scope: local
bookworm: resolved (fixed in 2.14-1)
bullseye: resolved (fixed in 2.14-1)
forky: resolved (fixe
debian
CVE-2018-19215P4LOWCVSS 7.8fixed in nasm 2.14-1 (bookworm)2018
CVE-2018-19215 [HIGH] CVE-2018-19215: nasm - Netwide Assembler (NASM) 2.14rc16 has a heap-based buffer over-read in expand_mm...
Netwide Assembler (NASM) 2.14rc16 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for the special cases of the % and $ and ! characters.
Scope: local
bookworm: resolved (fixed in 2.14-1)
bullseye: resolved (fixed in 2.14-1)
forky: resolved (fixed in 2.14-1)
sid: resolved (fixed in 2.14-1)
trixie: resolved (fixed in 2.14-1)
debian
CVE-2018-8881P4LOWCVSS 7.3fixed in nasm 2.13.02-0.1 (bookworm)2018
CVE-2018-8881 [HIGH] CVE-2018-8881: nasm - Netwide Assembler (NASM) 2.13.02rc2 has a heap-based buffer over-read in the fun...
Netwide Assembler (NASM) 2.13.02rc2 has a heap-based buffer over-read in the function tokenize in asm/preproc.c, related to an unterminated string.
Scope: local
bookworm: resolved (fixed in 2.13.02-0.1)
bullseye: resolved (fixed in 2.13.02-0.1)
forky: resolved (fixed in 2.13.02-0.1)
sid: resolved (fixed in 2.13.02-0.1)
trixie: resolved (fixed in 2.13.02-0.1)
debian
CVE-2019-20352P4LOWCVSS 7.1fixed in nasm 2.15.04-1 (bookworm)2019
CVE-2019-20352 [HIGH] CVE-2019-20352: nasm - In Netwide Assembler (NASM) 2.15rc0, a heap-based buffer over-read occurs (via a...
In Netwide Assembler (NASM) 2.15rc0, a heap-based buffer over-read occurs (via a crafted .asm file) in set_text_free when called from expand_one_smacro in asm/preproc.c.
Scope: local
bookworm: resolved (fixed in 2.15.04-1)
bullseye: resolved (fixed in 2.15.04-1)
forky: resolved (fixed in 2.15.04-1)
sid: resolved (fixed in 2.15.04-1)
trixie: resolved (fixed in 2.15.04-1
debian
CVE-2018-1000667P4LOWCVSS 5.5fixed in nasm 2.14-1 (bookworm)2018
CVE-2018-1000667 [MEDIUM] CVE-2018-1000667: nasm - NASM nasm-2.13.03 nasm- 2.14rc15 version 2.14rc15 and earlier contains a memory ...
NASM nasm-2.13.03 nasm- 2.14rc15 version 2.14rc15 and earlier contains a memory corruption (crashed) of nasm when handling a crafted file due to function assemble_file(inname, depend_ptr) at asm/nasm.c:482. vulnerability in function assemble_file(inname, depend_ptr) at asm/nasm.c:482. that can result in aborting/crash nasm program. This attack appear to be exploi
debian
CVE-2017-17817P4MEDIUMCVSS 5.5fixed in nasm 2.13.02-0.1 (bookworm)2017
CVE-2017-17817 [MEDIUM] CVE-2017-17817: nasm - In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in pp_verror in a...
In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in pp_verror in asm/preproc.c that will cause a remote denial of service attack.
Scope: local
bookworm: resolved (fixed in 2.13.02-0.1)
bullseye: resolved (fixed in 2.13.02-0.1)
forky: resolved (fixed in 2.13.02-0.1)
sid: resolved (fixed in 2.13.02-0.1)
trixie: resolved (fixed in 2.13.02-0.1)
debian
CVE-2017-17811P4HIGHCVSS 7.8fixed in nasm 2.13.02-0.1 (bookworm)2017
CVE-2017-17811 [HIGH] CVE-2017-17811: nasm - In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer overflow that ...
In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer overflow that will cause a remote denial of service attack, related to a strcpy in paste_tokens in asm/preproc.c, a similar issue to CVE-2017-11111.
Scope: local
bookworm: resolved (fixed in 2.13.02-0.1)
bullseye: resolved (fixed in 2.13.02-0.1)
forky: resolved (fixed in 2.13.02-0.1)
sid: resolved (fixed
debian
1 / 3Next →