Netwide Assembler

Vendor:

First CVE: Jan 10, 2005 · Active for 21 years

75
Total CVEs
More Total CVEs than 99% of tracked products
6.3
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Netwide Assembler over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 10, 2005
21 years ago
Most Recent CVE
Apr 10, 2026
105 days ago

CVE Severity & Scoring

Netwide Assembler75 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local68 (90.7%)
Network4 (5.3%)
Unknown3 (4.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low72 (96.0%)
High0 (0.0%)
Unknown3 (4.0%)
User Interaction
None10 (13.3%)
Unknown3 (4.0%)
Required62 (82.7%)
Privileges Required
Low8 (10.7%)
High0 (0.0%)
None64 (85.3%)
Unknown3 (4.0%)

Top CVEs

Signals from CVEs in this product scope (75 CVEs).

75 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Buffer overflow in the error function in preproc.c for NASM 0.98.38 1.2 allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2005-1
Jan 10, 200510.051NOYES
NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the global depend_file and later dereferenc
Apr 10, 20269.632NONO
asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a denial of service via a crafted file.
Sep 6, 20185.532NOYES
Off-by-one error in the ppscan function (preproc.c) in Netwide Assembler (NASM) 2.02 allows context-dependent attackers to cause a denial of service (crash) and possibly execute ar
Jun 16, 20086.831NOYES
In NASM 2.15.04rc3, there is a double-free vulnerability in pp_tokline asm/preproc.c. This is fixed in commit 8806c3ca007b84accac21dd88b900fb03614ceb7.
Sep 4, 20209.828NONO
NASM’s disasm() function contains a stack based buffer overflow when formatting disassembly output, allowing an attacker triggered out-of-bounds write when `slen` exceeds the buffe
Apr 10, 20267.526NONO
A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected is the function parse_line of the file parser.c. The manipulation leads to stack-based buffer overflow. Th
Aug 11, 20257.825NONO
A vulnerability was identified in NASM Netwide Assember 2.17rc0. This issue affects the function assemble_file of the file nasm.c. The manipulation leads to stack-based buffer over
Aug 11, 20257.825NONO
A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected by this issue is the function do_directive of the file preproc.c. The manipulation leads to use after free
Aug 11, 20257.825NONO
NASM v2.16 was discovered to contain a heap buffer overflow in the component quote_for_pmake() asm/nasm.c:856
Mar 29, 20237.825NONO

Exploit Exposure

Signals from CVEs in this product scope (75 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
4.0% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (75 CVEs).

Media Mentions

Signals from CVEs in this product scope (75 CVEs).

Top CNAs Publishing CVEs For Netwide Assembler

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.0237.50.4%00
2.1757.30.3%00
2.16.0217.80.4%00
2.16.0116.10.4%00
2.16135.70.3%00
2.15.0419.81.4%00
2.1575.70.6%00
2.14.0315.50.5%00
2.14.0236.30.7%00
2.14.01rc515.50.8%00
2.14.055.52.9%01
2.14195.81.6%01
2.13.0237.60.6%00
2.1317.81.4%00
2.0216.810.5%01
12.1456.41.1%00
0.98.38110.017.9%01