Debian Nasm vulnerabilities
46 known vulnerabilities affecting debian/nasm.
Total CVEs
46
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH6MEDIUM11LOW26
Vulnerabilities
Page 2 of 3
CVE-2005-1194P4CRITICALCVSS 10.0fixed in nasm 0.98.38-1.2 (bookworm)2005
CVE-2005-1194 [CRITICAL] CVE-2005-1194: nasm - Stack-based buffer overflow in the ieee_putascii function for nasm 0.98 and earl...
Stack-based buffer overflow in the ieee_putascii function for nasm 0.98 and earlier allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2004-1287.
Scope: local
bookworm: resolved (fixed in 0.98.38-1.2)
bullseye: resolved (fixed in 0.98.38-1.2)
forky: resolved (fixed in 0.98.38-1.2)
sid: resolved (fixed in 0.98.38-1.2)
debian
CVE-2017-17816P4MEDIUMCVSS 5.5fixed in nasm 2.13.02-0.1 (bookworm)2017
CVE-2017-17816 [MEDIUM] CVE-2017-17816: nasm - In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in pp_getline in ...
In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in pp_getline in asm/preproc.c that will cause a remote denial of service attack.
Scope: local
bookworm: resolved (fixed in 2.13.02-0.1)
bullseye: resolved (fixed in 2.13.02-0.1)
forky: resolved (fixed in 2.13.02-0.1)
sid: resolved (fixed in 2.13.02-0.1)
trixie: resolved (fixed in 2.13.02-0.1)
debian
CVE-2017-17814P4MEDIUMCVSS 5.5fixed in nasm 2.13.02-0.1 (bookworm)2017
CVE-2017-17814 [MEDIUM] CVE-2017-17814: nasm - In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in do_directive i...
In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in do_directive in asm/preproc.c that will cause a remote denial of service attack.
Scope: local
bookworm: resolved (fixed in 2.13.02-0.1)
bullseye: resolved (fixed in 2.13.02-0.1)
forky: resolved (fixed in 2.13.02-0.1)
sid: resolved (fixed in 2.13.02-0.1)
trixie: resolved (fixed in 2.13.02-0.1)
debian
CVE-2017-17813P4MEDIUMCVSS 5.5fixed in nasm 2.13.02-0.1 (bookworm)2017
CVE-2017-17813 [MEDIUM] CVE-2017-17813: nasm - In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in the pp_list_on...
In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in the pp_list_one_macro function in asm/preproc.c that will cause a remote denial of service attack, related to mishandling of line-syntax errors.
Scope: local
bookworm: resolved (fixed in 2.13.02-0.1)
bullseye: resolved (fixed in 2.13.02-0.1)
forky: resolved (fixed in 2.13.02-0.1)
sid: resolved (fixed i
debian
CVE-2020-21686P4MEDIUMCVSS 5.5fixed in nasm 2.15.04-1 (bookworm)2020
CVE-2020-21686 [MEDIUM] CVE-2020-21686: nasm - A stack-use-after-scope issue discovered in expand_mmac_params function in prepr...
A stack-use-after-scope issue discovered in expand_mmac_params function in preproc.c in nasm before 2.15.04 allows remote attackers to cause a denial of service via crafted asm file.
Scope: local
bookworm: resolved (fixed in 2.15.04-1)
bullseye: resolved (fixed in 2.15.04-1)
forky: resolved (fixed in 2.15.04-1)
sid: resolved (fixed in 2.15.04-1)
trixie: resolved (fix
debian
CVE-2017-17812P4MEDIUMCVSS 5.5fixed in nasm 2.13.02-0.1 (bookworm)2017
CVE-2017-17812 [MEDIUM] CVE-2017-17812: nasm - In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer over-read in t...
In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer over-read in the function detoken() in asm/preproc.c that will cause a remote denial of service attack.
Scope: local
bookworm: resolved (fixed in 2.13.02-0.1)
bullseye: resolved (fixed in 2.13.02-0.1)
forky: resolved (fixed in 2.13.02-0.1)
sid: resolved (fixed in 2.13.02-0.1)
trixie: resolved (fixed in
debian
CVE-2017-17815P4MEDIUMCVSS 5.5fixed in nasm 2.13.02-0.1 (bookworm)2017
CVE-2017-17815 [MEDIUM] CVE-2017-17815: nasm - In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in is_mm...
In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in is_mmacro() in asm/preproc.c that will cause a remote denial of service attack, because of a missing check for the relationship between minimum and maximum parameter counts.
Scope: local
bookworm: resolved (fixed in 2.13.02-0.1)
bullseye: resolved (fixed in 2.13.02-0.1)
forky: resolved (fixed
debian
CVE-2017-17820P4MEDIUMCVSS 5.5fixed in nasm 2.13.02-0.1 (bookworm)2017
CVE-2017-17820 [MEDIUM] CVE-2017-17820: nasm - In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in pp_list_one_ma...
In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in pp_list_one_macro in asm/preproc.c that will lead to a remote denial of service attack, related to mishandling of operand-type errors.
Scope: local
bookworm: resolved (fixed in 2.13.02-0.1)
bullseye: resolved (fixed in 2.13.02-0.1)
forky: resolved (fixed in 2.13.02-0.1)
sid: resolved (fixed in 2.13.02-
debian
CVE-2017-17819P4MEDIUMCVSS 5.5fixed in nasm 2.13.02-0.1 (bookworm)2017
CVE-2017-17819 [MEDIUM] CVE-2017-17819: nasm - In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in the f...
In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in the function find_cc() in asm/preproc.c that will cause a remote denial of service attack, because pointers associated with skip_white_ calls are not validated.
Scope: local
bookworm: resolved (fixed in 2.13.02-0.1)
bullseye: resolved (fixed in 2.13.02-0.1)
forky: resolved (fixed in 2.13.02-0.
debian
CVE-2020-21528P4LOWCVSS 5.5fixed in nasm 2.16.01-1 (bookworm)2020
CVE-2020-21528 [MEDIUM] CVE-2020-21528: nasm - A Segmentation Fault issue discovered in in ieee_segment function in outieee.c i...
A Segmentation Fault issue discovered in in ieee_segment function in outieee.c in nasm 2.14.03 and 2.15 allows remote attackers to cause a denial of service via crafted assembly file.
Scope: local
bookworm: resolved (fixed in 2.16.01-1)
bullseye: open
forky: resolved (fixed in 2.16.01-1)
sid: resolved (fixed in 2.16.01-1)
trixie: resolved (fixed in 2.16.01-1)
debian
CVE-2017-17810P4MEDIUMCVSS 5.5fixed in nasm 2.13.02-0.1 (bookworm)2017
CVE-2017-17810 [MEDIUM] CVE-2017-17810: nasm - In Netwide Assembler (NASM) 2.14rc0, there is a "SEGV on unknown address" that w...
In Netwide Assembler (NASM) 2.14rc0, there is a "SEGV on unknown address" that will cause a remote denial of service attack, because asm/preproc.c mishandles macro calls that have the wrong number of arguments.
Scope: local
bookworm: resolved (fixed in 2.13.02-0.1)
bullseye: resolved (fixed in 2.13.02-0.1)
forky: resolved (fixed in 2.13.02-0.1)
sid: resolved (fixed i
debian
CVE-2017-14228P4LOWCVSS 5.5fixed in nasm 2.13.02-0.1 (bookworm)2017
CVE-2017-14228 [MEDIUM] CVE-2017-14228: nasm - In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in the f...
In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in the function paste_tokens() in preproc.c, aka a NULL pointer dereference. It will lead to remote denial of service.
Scope: local
bookworm: resolved (fixed in 2.13.02-0.1)
bullseye: resolved (fixed in 2.13.02-0.1)
forky: resolved (fixed in 2.13.02-0.1)
sid: resolved (fixed in 2.13.02-0.1)
trixi
debian
CVE-2018-20535P4LOWCVSS 5.5fixed in nasm 2.15.04-1 (bookworm)2018
CVE-2018-20535 [MEDIUM] CVE-2018-20535: nasm - There is a use-after-free at asm/preproc.c (function pp_getline) in Netwide Asse...
There is a use-after-free at asm/preproc.c (function pp_getline) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service during a line-number increment attempt.
Scope: local
bookworm: resolved (fixed in 2.15.04-1)
bullseye: resolved (fixed in 2.15.04-1)
forky: resolved (fixed in 2.15.04-1)
sid: resolved (fixed in 2.15.04-1)
trixie: resolved (fixed in
debian
CVE-2022-29654P4LOWCVSS 5.5fixed in nasm 2.16.01-1 (bookworm)2022
CVE-2022-29654 [MEDIUM] CVE-2022-29654: nasm - Buffer overflow vulnerability in quote_for_pmake in asm/nasm.c in nasm before 2....
Buffer overflow vulnerability in quote_for_pmake in asm/nasm.c in nasm before 2.15.05 allows attackers to cause a denial of service via crafted file.
Scope: local
bookworm: resolved (fixed in 2.16.01-1)
bullseye: open
forky: resolved (fixed in 2.16.01-1)
sid: resolved (fixed in 2.16.01-1)
trixie: resolved (fixed in 2.16.01-1)
debian
CVE-2020-18780P4LOWCVSS 5.5fixed in nasm 2.15.04-1 (bookworm)2020
CVE-2020-18780 [MEDIUM] CVE-2020-18780: nasm - A Use After Free vulnerability in function new_Token in asm/preproc.c in nasm 2....
A Use After Free vulnerability in function new_Token in asm/preproc.c in nasm 2.14.02 allows attackers to cause a denial of service via crafted nasm command.
Scope: local
bookworm: resolved (fixed in 2.15.04-1)
bullseye: resolved (fixed in 2.15.04-1)
forky: resolved (fixed in 2.15.04-1)
sid: resolved (fixed in 2.15.04-1)
trixie: resolved (fixed in 2.15.04-1)
debian
CVE-2018-10016P4MEDIUMCVSS 5.5fixed in nasm 2.14-1 (bookworm)2018
CVE-2018-10016 [MEDIUM] CVE-2018-10016: nasm - Netwide Assembler (NASM) 2.14rc0 has a division-by-zero vulnerability in the exp...
Netwide Assembler (NASM) 2.14rc0 has a division-by-zero vulnerability in the expr5 function in asm/eval.c via a malformed input file.
Scope: local
bookworm: resolved (fixed in 2.14-1)
bullseye: resolved (fixed in 2.14-1)
forky: resolved (fixed in 2.14-1)
sid: resolved (fixed in 2.14-1)
trixie: resolved (fixed in 2.14-1)
debian
CVE-2018-19755P4LOWCVSS 5.5fixed in nasm 2.15.02-1 (bookworm)2018
CVE-2018-19755 [MEDIUM] CVE-2018-19755: nasm - There is an illegal address access at asm/preproc.c (function: is_mmacro) in Net...
There is an illegal address access at asm/preproc.c (function: is_mmacro) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service (out-of-bounds array access) because a certain conversion can result in a negative integer.
Scope: local
bookworm: resolved (fixed in 2.15.02-1)
bullseye: resolved (fixed in 2.15.02-1)
forky: resolved (fixed in 2.15.02-1)
debian
CVE-2020-21685P4LOWCVSS 5.5fixed in nasm 2.15.04-1 (bookworm)2020
CVE-2020-21685 [MEDIUM] CVE-2020-21685: nasm - Buffer Overflow vulnerability in hash_findi function in hashtbl.c in nasm 2.15rc...
Buffer Overflow vulnerability in hash_findi function in hashtbl.c in nasm 2.15rc0 allows remote attackers to cause a denial of service via crafted asm file.
Scope: local
bookworm: resolved (fixed in 2.15.04-1)
bullseye: resolved (fixed in 2.15.04-1)
forky: resolved (fixed in 2.15.04-1)
sid: resolved (fixed in 2.15.04-1)
trixie: resolved (fixed in 2.15.04-1)
debian
CVE-2020-21687P4LOWCVSS 5.5fixed in nasm 2.15.04-1 (bookworm)2020
CVE-2020-21687 [MEDIUM] CVE-2020-21687: nasm - Buffer Overflow vulnerability in scan function in stdscan.c in nasm 2.15rc0 allo...
Buffer Overflow vulnerability in scan function in stdscan.c in nasm 2.15rc0 allows remote attackers to cause a denial of service via crafted asm file.
Scope: local
bookworm: resolved (fixed in 2.15.04-1)
bullseye: resolved (fixed in 2.15.04-1)
forky: resolved (fixed in 2.15.04-1)
sid: resolved (fixed in 2.15.04-1)
trixie: resolved (fixed in 2.15.04-1)
debian
CVE-2018-16999P4LOWCVSS 5.5fixed in nasm 2.14-1 (bookworm)2018
CVE-2018-16999 [MEDIUM] CVE-2018-16999: nasm - Netwide Assembler (NASM) 2.14rc15 has an invalid memory write (segmentation faul...
Netwide Assembler (NASM) 2.14rc15 has an invalid memory write (segmentation fault) in expand_smacro in preproc.c, which allows attackers to cause a denial of service via a crafted input file.
Scope: local
bookworm: resolved (fixed in 2.14-1)
bullseye: resolved (fixed in 2.14-1)
forky: resolved (fixed in 2.14-1)
sid: resolved (fixed in 2.14-1)
trixie: resolved (fixed
debian