Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Tortall

First CVE: Jul 26, 2022Active for: 4 yearsTotal CVEs: 19
20.6
VTI Score
Low

Tortall maintains Yasm, an assembler tool widely embedded in build pipelines and compiler infrastructure, and the vendor's vulnerability footprint concentrates on memory-safety issues typical of a C-based code generator: NULL pointer dereferences, use-after-free conditions, buffer overflows, and memory-management errors such as improper release and heap-corruption patterns. Defenders should treat Yasm vulnerabilities as relevant to any development or embedded build environment that depends on this assembler; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
19
Total CVEs
More Total CVEs than 96% of tracked vendors
6.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
5.5
Avg CVSS Score
Higher Avg CVSS Score than 22% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Tortall over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 26, 2022
3 years ago
Most Recent CVE
Jan 18, 2024
918 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-33455MEDIUM
An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in do_directive() in modules/preprocs/nasm/nasm-pp.c.
Jul 26, 20225.520NONO
CVE-2021-33454MEDIUM
An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in yasm_expr_get_intnum() in libyasm/expr.c.
Jul 26, 20225.520NONO
CVE-2023-31973MEDIUM
yasm v1.3.0 was discovered to contain a use after free via the function expand_mmac_params at /nasm/nasm-pp.c. Note: Multiple third parties dispute this as a bug and not a vulnerab
May 9, 20235.519NONO
CVE-2023-31974MEDIUM
yasm v1.3.0 was discovered to contain a use after free via the function error at /nasm/nasm-pp.c. Note: Multiple third parties dispute this as a bug and not a vulnerability accordi
May 9, 20235.519NONO
CVE-2023-31972MEDIUM
yasm v1.3.0 was discovered to contain a use after free via the function pp_getline at /nasm/nasm-pp.c. Note: Multiple third parties dispute this as a bug and not a vulnerability ac
May 9, 20235.519NONO
CVE-2021-33468MEDIUM
An issue was discovered in yasm version 1.3.0. There is a use-after-free in error() in modules/preprocs/nasm/nasm-pp.c.
Jul 26, 20225.519NONO
CVE-2021-33467MEDIUM
An issue was discovered in yasm version 1.3.0. There is a use-after-free in pp_getline() in modules/preprocs/nasm/nasm-pp.c.
Jul 26, 20225.519NONO
CVE-2021-33466MEDIUM
An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in expand_smacro() in modules/preprocs/nasm/nasm-pp.c.
Jul 26, 20225.519NONO
CVE-2021-33465MEDIUM
An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in expand_mmacro() in modules/preprocs/nasm/nasm-pp.c.
Jul 26, 20225.519NONO
CVE-2021-33464MEDIUM
An issue was discovered in yasm version 1.3.0. There is a heap-buffer-overflow in inc_fopen() in modules/preprocs/nasm/nasm-pp.c.
Jul 26, 20225.519NONO
View all 19 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products19 CVEs
100%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
Medium
Attack Vector
Local19 (100.0%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (5.3%)
Unknown0 (0.0%)
Required18 (94.7%)
Privileges Required
Low1 (5.3%)
High0 (0.0%)
None18 (94.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Tortall.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Tortall — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Tortall's Products

View all 1 CNAs →

Top CWEs