5.5

CVE-2018-16517

Exploit
asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a denial of service via a crafted file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nasm ≫ Netwide Assembler Version <= 2.13.03
Nasm ≫ Netwide Assembler Version 2.14 Update rc15
Nasm ≫ Netwide Assembler Version 2.14.0 Update rc1
Nasm ≫ Netwide Assembler Version 2.14.0 Update rc10
Nasm ≫ Netwide Assembler Version 2.14.0 Update rc11
Nasm ≫ Netwide Assembler Version 2.14.0 Update rc12
Nasm ≫ Netwide Assembler Version 2.14.0 Update rc13
Nasm ≫ Netwide Assembler Version 2.14.0 Update rc14
Nasm ≫ Netwide Assembler Version 2.14.0 Update rc2
Nasm ≫ Netwide Assembler Version 2.14.0 Update rc3
Nasm ≫ Netwide Assembler Version 2.14.0 Update rc4
Nasm ≫ Netwide Assembler Version 2.14.0 Update rc5
Nasm ≫ Netwide Assembler Version 2.14.0 Update rc6
Nasm ≫ Netwide Assembler Version 2.14.0 Update rc7
Nasm ≫ Netwide Assembler Version 2.14.0 Update rc8
Nasm ≫ Netwide Assembler Version 2.14.0 Update rc9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.17% 0.914
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00015.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00017.html
Third Party Advisory
Mailing List
http://packetstormsecurity.com/files/152566/Netwide-Assembler-NASM-2.14rc15-Null-Pointer-Dereference.html
Third Party Advisory
Exploit
VDB Entry
https://bugzilla.nasm.us/show_bug.cgi?id=3392513
Third Party Advisory
Exploit
Issue Tracking
https://fakhrizulkifli.github.io/CVE-2018-16517.html
Third Party Advisory
Exploit
https://www.exploit-db.com/exploits/46726/
Third Party Advisory
Exploit
VDB Entry