Netwide Assembler
Vendor:
First CVE: Jan 10, 2005 · Active for 21 years
75
Total CVEs
More Total CVEs than 99% of tracked products
6.3
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Netwide Assembler over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 10, 2005
21 years ago
Most Recent CVE
Apr 10, 2026
105 days ago
CVE Severity & Scoring
Netwide Assembler75 CVEs
68%
28%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local68 (90.7%)
Network4 (5.3%)
Unknown3 (4.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low72 (96.0%)
High0 (0.0%)
Unknown3 (4.0%)
User Interaction
None10 (13.3%)
Unknown3 (4.0%)
Required62 (82.7%)
Privileges Required
Low8 (10.7%)
High0 (0.0%)
None64 (85.3%)
Unknown3 (4.0%)
Top CVEs
Signals from CVEs in this product scope (75 CVEs).
75 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-1287HIGH Buffer overflow in the error function in preproc.c for NASM 0.98.38 1.2 allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2005-1 | Jan 10, 2005 | 10.0 | 51 | NO | YES |
CVE-2026-6068CRITICAL NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the global depend_file and later dereferenc | Apr 10, 2026 | 9.6 | 32 | NO | NO |
CVE-2018-16517MEDIUM asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a denial of service via a crafted file. | Sep 6, 2018 | 5.5 | 32 | NO | YES |
CVE-2008-2719MEDIUM Off-by-one error in the ppscan function (preproc.c) in Netwide Assembler (NASM) 2.02 allows context-dependent attackers to cause a denial of service (crash) and possibly execute ar | Jun 16, 2008 | 6.8 | 31 | NO | YES |
CVE-2020-24978CRITICAL In NASM 2.15.04rc3, there is a double-free vulnerability in pp_tokline asm/preproc.c. This is fixed in commit 8806c3ca007b84accac21dd88b900fb03614ceb7. | Sep 4, 2020 | 9.8 | 28 | NO | NO |
CVE-2026-6069HIGH NASM’s disasm() function contains a stack based buffer overflow when formatting disassembly output, allowing an attacker triggered out-of-bounds write when `slen` exceeds the buffe | Apr 10, 2026 | 7.5 | 26 | NO | NO |
CVE-2025-8846HIGH A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected is the function parse_line of the file parser.c. The manipulation leads to stack-based buffer overflow. Th | Aug 11, 2025 | 7.8 | 25 | NO | NO |
CVE-2025-8845HIGH A vulnerability was identified in NASM Netwide Assember 2.17rc0. This issue affects the function assemble_file of the file nasm.c. The manipulation leads to stack-based buffer over | Aug 11, 2025 | 7.8 | 25 | NO | NO |
CVE-2025-8842HIGH A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected by this issue is the function do_directive of the file preproc.c. The manipulation leads to use after free | Aug 11, 2025 | 7.8 | 25 | NO | NO |
CVE-2022-44370HIGH NASM v2.16 was discovered to contain a heap buffer overflow in the component quote_for_pmake() asm/nasm.c:856 | Mar 29, 2023 | 7.8 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (75 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
4.0% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (75 CVEs).
Media Mentions
Signals from CVEs in this product scope (75 CVEs).
Top CNAs Publishing CVEs For Netwide Assembler
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.02 | 3 | 7.5 | 0.4% | 0 | 0 |
| 2.17 | 5 | 7.3 | 0.3% | 0 | 0 |
| 2.16.02 | 1 | 7.8 | 0.4% | 0 | 0 |
| 2.16.01 | 1 | 6.1 | 0.4% | 0 | 0 |
| 2.16 | 13 | 5.7 | 0.3% | 0 | 0 |
| 2.15.04 | 1 | 9.8 | 1.4% | 0 | 0 |
| 2.15 | 7 | 5.7 | 0.6% | 0 | 0 |
| 2.14.03 | 1 | 5.5 | 0.5% | 0 | 0 |
| 2.14.02 | 3 | 6.3 | 0.7% | 0 | 0 |
| 2.14.01rc5 | 1 | 5.5 | 0.8% | 0 | 0 |
| 2.14.0 | 5 | 5.5 | 2.9% | 0 | 1 |
| 2.14 | 19 | 5.8 | 1.6% | 0 | 1 |
| 2.13.02 | 3 | 7.6 | 0.6% | 0 | 0 |
| 2.13 | 1 | 7.8 | 1.4% | 0 | 0 |
| 2.02 | 1 | 6.8 | 10.5% | 0 | 1 |
| 12.14 | 5 | 6.4 | 1.1% | 0 | 0 |
| 0.98.38 | 1 | 10.0 | 17.9% | 0 | 1 |