Yasm is a modular assembler project that sits in the developer toolchain and build systems for x86 and x86-64 assembly compilation, a niche but structurally important role in binary construction. Its vulnerability history centers on the single Yasm product and recurs through weakness classes including out-of-bounds writes, NULL-pointer dereferences, uncontrolled resource consumption, and use-after-free conditions, reflecting the memory-handling and parser demands of a low-level code transformation tool. Current exploitation and severity figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yasm Project over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-31724HIGH yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the function do_directive at /nasm/nasm-pp.c. | May 17, 2023 | 7.8 | 24 | NO | NO |
CVE-2023-31725MEDIUM yasm 1.3.0.55.g101bc was discovered to contain a heap-use-after-free via the function expand_mmac_params at yasm/modules/preprocs/nasm/nasm-pp.c. | May 17, 2023 | 5.5 | 20 | NO | NO |
CVE-2023-31723MEDIUM yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the function expand_mmac_params at /nasm/nasm-pp.c. | May 17, 2023 | 5.5 | 20 | NO | NO |
CVE-2023-30402MEDIUM YASM v1.3.0 was discovered to contain a heap overflow via the function handle_dot_label at /nasm/nasm-token.re. Note: This has been disputed by third parties who argue this is a bu | Apr 25, 2023 | 5.5 | 20 | NO | NO |
CVE-2023-29583MEDIUM yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr5 at /nasm/nasm-parse.c. Note: This has been disputed by third parties who argue this is | Apr 24, 2023 | 5.5 | 20 | NO | NO |
CVE-2023-29582MEDIUM yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr1 at /nasm/nasm-parse.c. Note: This has been disputed by third parties who argue this is | Apr 24, 2023 | 5.5 | 20 | NO | NO |
CVE-2023-29579MEDIUM yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the component yasm/yasm+0x43b466 in vsprintf. Note: This has been disputed by third parties who argue this is a | Apr 24, 2023 | 5.5 | 20 | NO | NO |
CVE-2023-29581MEDIUM yasm 1.3.0.55.g101bc has a segmentation violation in the function delete_Token at modules/preprocs/nasm/nasm-pp.c. NOTE: although a libyasm application could become unavailable if | Apr 12, 2023 | 5.5 | 20 | NO | NO |
CVE-2023-29580MEDIUM yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the component yasm_expr_create at /libyasm/expr.c. | Apr 12, 2023 | 5.5 | 20 | NO | NO |
CVE-2023-49558MEDIUM An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_mmac_params function in the modules/preprocs/nasm/nasm-pp.c component. | Jan 3, 2024 | 5.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yasm Project.
Media articles that mention a CVE ID that affects a product developed by Yasm Project — matched by CVE ID, not by vendor name.