Логотип exploitDog
bind:CVE-2017-10686
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-10686

Количество 9

Количество 9

ubuntu логотип

CVE-2017-10686

больше 8 лет назад

In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vulnerabilities in the tool nasm. The related heap is allocated in the token() function and freed in the detoken() function (called by pp_getline()) - it is used again at multiple positions later that could cause multiple damages. For example, it causes a corrupted double-linked list in detoken(), a double free or corruption in delete_Token(), and an out-of-bounds write in detoken(). It has a high possibility to lead to a remote code execution attack.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2017-10686

больше 8 лет назад

In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vulnerabilities in the tool nasm. The related heap is allocated in the token() function and freed in the detoken() function (called by pp_getline()) - it is used again at multiple positions later that could cause multiple damages. For example, it causes a corrupted double-linked list in detoken(), a double free or corruption in delete_Token(), and an out-of-bounds write in detoken(). It has a high possibility to lead to a remote code execution attack.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2017-10686

больше 8 лет назад

In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vulnerabilities in the tool nasm. The related heap is allocated in the token() function and freed in the detoken() function (called by pp_getline()) - it is used again at multiple positions later that could cause multiple damages. For example, it causes a corrupted double-linked list in detoken(), a double free or corruption in delete_Token(), and an out-of-bounds write in detoken(). It has a high possibility to lead to a remote code execution attack.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2017-10686

больше 8 лет назад

In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after ...

CVSS3: 7.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:2045-1

больше 8 лет назад

Security update for nasm

EPSS: Низкий
github логотип

GHSA-vppv-9vcp-9fcg

больше 3 лет назад

In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vulnerabilities in the tool nasm. The related heap is allocated in the token() function and freed in the detoken() function (called by pp_getline()) - it is used again at multiple positions later that could cause multiple damages. For example, it causes a corrupted double-linked list in detoken(), a double free or corruption in delete_Token(), and an out-of-bounds write in detoken(). It has a high possibility to lead to a remote code execution attack.

CVSS3: 7.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2017:2125-1

больше 8 лет назад

Security update for nasm

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:2044-1

больше 8 лет назад

Security update for nasm

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:14246-1

около 6 лет назад

Security update for Mozilla Firefox

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-10686

In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vulnerabilities in the tool nasm. The related heap is allocated in the token() function and freed in the detoken() function (called by pp_getline()) - it is used again at multiple positions later that could cause multiple damages. For example, it causes a corrupted double-linked list in detoken(), a double free or corruption in delete_Token(), and an out-of-bounds write in detoken(). It has a high possibility to lead to a remote code execution attack.

CVSS3: 7.8
1%
Низкий
больше 8 лет назад
redhat логотип
CVE-2017-10686

In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vulnerabilities in the tool nasm. The related heap is allocated in the token() function and freed in the detoken() function (called by pp_getline()) - it is used again at multiple positions later that could cause multiple damages. For example, it causes a corrupted double-linked list in detoken(), a double free or corruption in delete_Token(), and an out-of-bounds write in detoken(). It has a high possibility to lead to a remote code execution attack.

CVSS3: 5.3
1%
Низкий
больше 8 лет назад
nvd логотип
CVE-2017-10686

In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vulnerabilities in the tool nasm. The related heap is allocated in the token() function and freed in the detoken() function (called by pp_getline()) - it is used again at multiple positions later that could cause multiple damages. For example, it causes a corrupted double-linked list in detoken(), a double free or corruption in delete_Token(), and an out-of-bounds write in detoken(). It has a high possibility to lead to a remote code execution attack.

CVSS3: 7.8
1%
Низкий
больше 8 лет назад
debian логотип
CVE-2017-10686

In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after ...

CVSS3: 7.8
1%
Низкий
больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:2045-1

Security update for nasm

1%
Низкий
больше 8 лет назад
github логотип
GHSA-vppv-9vcp-9fcg

In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vulnerabilities in the tool nasm. The related heap is allocated in the token() function and freed in the detoken() function (called by pp_getline()) - it is used again at multiple positions later that could cause multiple damages. For example, it causes a corrupted double-linked list in detoken(), a double free or corruption in delete_Token(), and an out-of-bounds write in detoken(). It has a high possibility to lead to a remote code execution attack.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2017:2125-1

Security update for nasm

больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:2044-1

Security update for nasm

больше 8 лет назад
suse-cvrf логотип
SUSE-SU-2019:14246-1

Security update for Mozilla Firefox

около 6 лет назад

Уязвимостей на страницу