Tortall maintains Yasm, an assembler tool widely embedded in build pipelines and compiler infrastructure, and the vendor's vulnerability footprint concentrates on memory-safety issues typical of a C-based code generator: NULL pointer dereferences, use-after-free conditions, buffer overflows, and memory-management errors such as improper release and heap-corruption patterns. Defenders should treat Yasm vulnerabilities as relevant to any development or embedded build environment that depends on this assembler; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tortall over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-33455MEDIUM An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in do_directive() in modules/preprocs/nasm/nasm-pp.c. | Jul 26, 2022 | 5.5 | 20 | NO | NO |
CVE-2021-33454MEDIUM An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in yasm_expr_get_intnum() in libyasm/expr.c. | Jul 26, 2022 | 5.5 | 20 | NO | NO |
CVE-2023-31973MEDIUM yasm v1.3.0 was discovered to contain a use after free via the function expand_mmac_params at /nasm/nasm-pp.c. Note: Multiple third parties dispute this as a bug and not a vulnerab | May 9, 2023 | 5.5 | 19 | NO | NO |
CVE-2023-31974MEDIUM yasm v1.3.0 was discovered to contain a use after free via the function error at /nasm/nasm-pp.c. Note: Multiple third parties dispute this as a bug and not a vulnerability accordi | May 9, 2023 | 5.5 | 19 | NO | NO |
CVE-2023-31972MEDIUM yasm v1.3.0 was discovered to contain a use after free via the function pp_getline at /nasm/nasm-pp.c. Note: Multiple third parties dispute this as a bug and not a vulnerability ac | May 9, 2023 | 5.5 | 19 | NO | NO |
CVE-2021-33468MEDIUM An issue was discovered in yasm version 1.3.0. There is a use-after-free in error() in modules/preprocs/nasm/nasm-pp.c. | Jul 26, 2022 | 5.5 | 19 | NO | NO |
CVE-2021-33467MEDIUM An issue was discovered in yasm version 1.3.0. There is a use-after-free in pp_getline() in modules/preprocs/nasm/nasm-pp.c. | Jul 26, 2022 | 5.5 | 19 | NO | NO |
CVE-2021-33466MEDIUM An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in expand_smacro() in modules/preprocs/nasm/nasm-pp.c. | Jul 26, 2022 | 5.5 | 19 | NO | NO |
CVE-2021-33465MEDIUM An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in expand_mmacro() in modules/preprocs/nasm/nasm-pp.c. | Jul 26, 2022 | 5.5 | 19 | NO | NO |
CVE-2021-33464MEDIUM An issue was discovered in yasm version 1.3.0. There is a heap-buffer-overflow in inc_fopen() in modules/preprocs/nasm/nasm-pp.c. | Jul 26, 2022 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tortall.
Media articles that mention a CVE ID that affects a product developed by Tortall — matched by CVE ID, not by vendor name.