Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Nasm

First CVE: Jan 10, 2005Active for: 22 yearsTotal CVEs: 75
35.5
VTI Score
Medium

Nasm maintains the Netwide Assembler, a widely used cross-platform assembly language compiler that, despite its narrow product focus, occupies a prominent place in the software build chain and development tooling landscape. The vendor's vulnerability profile concentrates on memory-safety issues across the assembler's parser and intermediate representation layers, with recurring classes including use-after-free conditions, out-of-bounds reads and writes, NULL-pointer dereferences, and improper memory-buffer restrictions. These weakness classes reflect the low-level nature of assembly processing and the complexity of managing heap state during compilation of untrusted or malformed input. Defenders should treat assembler updates as part of build-chain security audits, particularly in contexts where the assembler processes external or generated assembly code; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
75
Total CVEs
More Total CVEs than 99% of tracked vendors
6.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Nasm over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 10, 2005
21 years ago
Most Recent CVE
Apr 10, 2026
105 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (75 CVEs).

75 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2004-1287HIGH
Buffer overflow in the error function in preproc.c for NASM 0.98.38 1.2 allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2005-1
Jan 10, 200510.051NOYES
CVE-2026-6068CRITICAL
NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the global depend_file and later dereferenc
Apr 10, 20269.632NONO
CVE-2018-16517MEDIUM
asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a denial of service via a crafted file.
Sep 6, 20185.532NOYES
CVE-2008-2719MEDIUM
Off-by-one error in the ppscan function (preproc.c) in Netwide Assembler (NASM) 2.02 allows context-dependent attackers to cause a denial of service (crash) and possibly execute ar
Jun 16, 20086.831NOYES
CVE-2020-24978CRITICAL
In NASM 2.15.04rc3, there is a double-free vulnerability in pp_tokline asm/preproc.c. This is fixed in commit 8806c3ca007b84accac21dd88b900fb03614ceb7.
Sep 4, 20209.828NONO
CVE-2026-6069HIGH
NASM’s disasm() function contains a stack based buffer overflow when formatting disassembly output, allowing an attacker triggered out-of-bounds write when `slen` exceeds the buffe
Apr 10, 20267.526NONO
CVE-2025-8846HIGH
A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected is the function parse_line of the file parser.c. The manipulation leads to stack-based buffer overflow. Th
Aug 11, 20257.825NONO
CVE-2025-8845HIGH
A vulnerability was identified in NASM Netwide Assember 2.17rc0. This issue affects the function assemble_file of the file nasm.c. The manipulation leads to stack-based buffer over
Aug 11, 20257.825NONO
CVE-2025-8842HIGH
A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected by this issue is the function do_directive of the file preproc.c. The manipulation leads to use after free
Aug 11, 20257.825NONO
CVE-2022-44370HIGH
NASM v2.16 was discovered to contain a heap buffer overflow in the component quote_for_pmake() asm/nasm.c:856
Mar 29, 20237.825NONO
View all 75 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products75 CVEs
68%
28%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local68 (90.7%)
Network4 (5.3%)
Unknown3 (4.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low72 (96.0%)
High0 (0.0%)
Unknown3 (4.0%)
User Interaction
None10 (13.3%)
Unknown3 (4.0%)
Required62 (82.7%)
Privileges Required
Low8 (10.7%)
High0 (0.0%)
None64 (85.3%)
Unknown3 (4.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (75 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
4.0% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Nasm.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Nasm — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Nasm's Products

View all 3 CNAs →

Top CWEs