Search CVE reports


Toggle filters

1 – 10 of 90 results


CVE-2026-6069

Medium priority
Needs evaluation

NASM’s disasm() function contains a stack based buffer overflow when formatting disassembly output, allowing an attacker triggered out-of-bounds write when `slen` exceeds the buffer capacity.

1 affected package

nasm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nasm Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-6068

Medium priority
Needs evaluation

NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the global depend_file and later dereferenced, as the response-file buffer is freed before...

1 affected package

nasm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nasm Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-6067

Medium priority
Needs evaluation

A heap buffer overflow vulnerability exists in the Netwide Assembler (NASM) due to a lack of bounds checking in the obj_directive() function. This vulnerability can be exploited by a user assembling a malicious .asm...

1 affected package

nasm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nasm Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-8846

Low priority
Needs evaluation

A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected is the function parse_line of the file parser.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally....

1 affected package

nasm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nasm Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-8845

Low priority
Needs evaluation

A vulnerability was identified in NASM Netwide Assember 2.17rc0. This issue affects the function assemble_file of the file nasm.c. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack on the...

1 affected package

nasm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nasm Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-8844

Low priority
Needs evaluation

A vulnerability was determined in NASM Netwide Assember 2.17rc0. This vulnerability affects the function parse_smacro_template of the file preproc.c. The manipulation leads to null pointer dereference. Attacking locally is a...

1 affected package

nasm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nasm Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-8843

Low priority
Needs evaluation

A vulnerability was found in NASM Netwide Assember 2.17rc0. This affects the function macho_no_dead_strip of the file outmacho.c. The manipulation leads to heap-based buffer overflow. Local access is required to approach this...

1 affected package

nasm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nasm Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-8842

Low priority
Needs evaluation

A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected by this issue is the function do_directive of the file preproc.c. The manipulation leads to use after free. An attack has to be approached locally. The...

1 affected package

nasm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nasm Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-38668

Medium priority
Vulnerable

Stack-based buffer over-read in disasm in nasm 2.16 allows attackers to cause a denial of service (crash).

1 affected package

nasm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nasm Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2023-38667

Medium priority
Vulnerable

Stack-based buffer over-read in function disasm in nasm 2.16 allows attackers to cause a denial of service.

1 affected package

nasm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nasm Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages