VulnerabilityModified
CVE-2004-1287
Buffer overflow in the error function in preproc.c for NASM 0.98.38 1.2 allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2005-1194.
HIGH 10.0EPSS 17.9%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 17.9%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in the error function in preproc.c for NASM 0.98.38 1.2 allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2005-1194.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 17.88% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- nasm/netwide assembler
- Source
- cve@mitre.org
References
- http://tigger.uic.edu/~jlongs2/holes/nasm.txtExploit, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2005-381.htmlNot Applicable
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18540Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11299Broken Link
- http://tigger.uic.edu/~jlongs2/holes/nasm.txtExploit, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2005-381.htmlNot Applicable
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18540Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11299Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.