Debian Yasm vulnerabilities
36 known vulnerabilities affecting debian/yasm.
Total CVEs
36
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2LOW34
Vulnerabilities
Page 1 of 2
CVE-2024-22653LOWCVSS 4.82024
CVE-2024-22653 [MEDIUM] CVE-2024-22653: yasm - yasm commit 9defefae was discovered to contain a NULL pointer dereference via th...
yasm commit 9defefae was discovered to contain a NULL pointer dereference via the yasm_section_bcs_append function at section.c.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
debian
CVE-2023-29579MEDIUMCVSS 5.5fixed in yasm 1.3.0-7 (forky)2023
CVE-2023-29579 [MEDIUM] CVE-2023-29579: yasm - yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the componen...
yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the component yasm/yasm+0x43b466 in vsprintf. Note: This has been disputed by third parties who argue this is a bug and not a security issue because yasm is a standalone program not designed to run untrusted code.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.3.0-7)
sid: reso
debian
CVE-2023-31973LOWCVSS 5.52023
CVE-2023-31973 [MEDIUM] CVE-2023-31973: yasm - yasm v1.3.0 was discovered to contain a use after free via the function expand_m...
yasm v1.3.0 was discovered to contain a use after free via the function expand_mmac_params at /nasm/nasm-pp.c. Note: Multiple third parties dispute this as a bug and not a vulnerability according to the YASM security policy.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
debian
CVE-2023-29580LOWCVSS 5.52023
CVE-2023-29580 [MEDIUM] CVE-2023-29580: yasm - yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the ...
yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the component yasm_expr_create at /libyasm/expr.c.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
debian
CVE-2023-37732LOWCVSS 5.52023
CVE-2023-37732 [MEDIUM] CVE-2023-37732: yasm - Yasm v1.3.0.78 was found prone to NULL Pointer Dereference in /libyasm/intnum.c ...
Yasm v1.3.0.78 was found prone to NULL Pointer Dereference in /libyasm/intnum.c and /elf/elf.c, which allows the attacker to cause a denial of service via a crafted file.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
debian
CVE-2023-31975LOWCVSS 3.32023
CVE-2023-31975 [LOW] CVE-2023-31975: yasm - yasm v1.3.0 was discovered to contain a memory leak via the function yasm_intnum...
yasm v1.3.0 was discovered to contain a memory leak via the function yasm_intnum_copy at /libyasm/intnum.c. Note: Multiple third parties dispute this as a bug and not a vulnerability according to the YASM security policy.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
debian
CVE-2023-31724LOWCVSS 7.82023
CVE-2023-31724 [HIGH] CVE-2023-31724: yasm - yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the ...
yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the function do_directive at /nasm/nasm-pp.c.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
debian
CVE-2023-31725LOWCVSS 5.52023
CVE-2023-31725 [MEDIUM] CVE-2023-31725: yasm - yasm 1.3.0.55.g101bc was discovered to contain a heap-use-after-free via the fun...
yasm 1.3.0.55.g101bc was discovered to contain a heap-use-after-free via the function expand_mmac_params at yasm/modules/preprocs/nasm/nasm-pp.c.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
debian
CVE-2023-30402LOWCVSS 5.52023
CVE-2023-30402 [MEDIUM] CVE-2023-30402: yasm - YASM v1.3.0 was discovered to contain a heap overflow via the function handle_do...
YASM v1.3.0 was discovered to contain a heap overflow via the function handle_dot_label at /nasm/nasm-token.re. Note: This has been disputed by third parties who argue this is a bug and not a security issue because yasm is a standalone program not designed to run untrusted code.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
debian
CVE-2023-51258LOWCVSS 5.52023
CVE-2023-51258 [MEDIUM] CVE-2023-51258: yasm - A memory leak issue discovered in YASM v.1.3.0 allows a local attacker to cause ...
A memory leak issue discovered in YASM v.1.3.0 allows a local attacker to cause a denial of service via the new_Token function in the modules/preprocs/nasm/nasm-pp:1512.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
debian
CVE-2023-49558LOWCVSS 5.52023
CVE-2023-49558 [MEDIUM] CVE-2023-49558: yasm - An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of se...
An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_mmac_params function in the modules/preprocs/nasm/nasm-pp.c component.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
debian
CVE-2023-29583LOWCVSS 5.52023
CVE-2023-29583 [MEDIUM] CVE-2023-29583: yasm - yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function...
yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr5 at /nasm/nasm-parse.c. Note: This has been disputed by third parties who argue this is a bug and not a security issue because yasm is a standalone program not designed to run untrusted code.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
debian
CVE-2023-31972LOWCVSS 5.52023
CVE-2023-31972 [MEDIUM] CVE-2023-31972: yasm - yasm v1.3.0 was discovered to contain a use after free via the function pp_getli...
yasm v1.3.0 was discovered to contain a use after free via the function pp_getline at /nasm/nasm-pp.c. Note: Multiple third parties dispute this as a bug and not a vulnerability according to the YASM security policy.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
debian
CVE-2023-49557LOWCVSS 5.52023
CVE-2023-49557 [MEDIUM] CVE-2023-49557: yasm - An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of se...
An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the yasm_section_bcs_first function in the libyasm/section.c component.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
debian
CVE-2023-49556LOWCVSS 5.52023
CVE-2023-49556 [MEDIUM] CVE-2023-49556: yasm - Buffer Overflow vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to...
Buffer Overflow vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expr_delete_term function in the libyasm/expr.c component.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
debian
CVE-2023-31974LOWCVSS 5.52023
CVE-2023-31974 [MEDIUM] CVE-2023-31974: yasm - yasm v1.3.0 was discovered to contain a use after free via the function error at...
yasm v1.3.0 was discovered to contain a use after free via the function error at /nasm/nasm-pp.c. Note: Multiple third parties dispute this as a bug and not a vulnerability according to the YASM security policy.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
debian
CVE-2023-29581LOWCVSS 5.52023
CVE-2023-29581 [MEDIUM] CVE-2023-29581: yasm - yasm 1.3.0.55.g101bc has a segmentation violation in the function delete_Token a...
yasm 1.3.0.55.g101bc has a segmentation violation in the function delete_Token at modules/preprocs/nasm/nasm-pp.c. NOTE: although a libyasm application could become unavailable if this were exploited, the vendor's position is that there is no security relevance because there is either supposed to be input validation before data reaches libyasm, or a sandbox in which
debian
CVE-2023-49554LOWCVSS 5.52023
CVE-2023-49554 [MEDIUM] CVE-2023-49554: yasm - Use After Free vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to ...
Use After Free vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the do_directive function in the modules/preprocs/nasm/nasm-pp.c component.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
debian
CVE-2023-29582LOWCVSS 5.52023
CVE-2023-29582 [MEDIUM] CVE-2023-29582: yasm - yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function...
yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr1 at /nasm/nasm-parse.c. Note: This has been disputed by third parties who argue this is a bug and not a security issue because yasm is a standalone program not designed to run untrusted code.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
debian
CVE-2023-31723LOWCVSS 5.52023
CVE-2023-31723 [MEDIUM] CVE-2023-31723: yasm - yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the ...
yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the function expand_mmac_params at /nasm/nasm-pp.c.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
debian
1 / 2Next →