Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2018-19215
Netwide Assembler (NASM) 2.14rc16 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for the special cases of the % and $ and ! characters.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.002
EPSS Ranking
45.1%
CVSS Severity
CVSS v3 Score
7.8
CVSS v2 Score
6.8
References
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00015.html
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00017.html
https://bugzilla.nasm.us/show_bug.cgi?id=3392525
https://repo.or.cz/nasm.git/commit/4b5b737d4991578b1918303dc0fd9c9ab5c7ce4f
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00015.html
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00017.html
https://bugzilla.nasm.us/show_bug.cgi?id=3392525
https://repo.or.cz/nasm.git/commit/4b5b737d4991578b1918303dc0fd9c9ab5c7ce4f
Products affected by CVE-2018-19215
Nasm
»
Netwide Assembler
»
Version:
12.14
cpe:2.3:a:nasm:netwide_assembler:12.14
Redhat
»
Enterprise Linux
»
Version:
5.0
cpe:2.3:o:redhat:enterprise_linux:5.0
Redhat
»
Enterprise Linux
»
Version:
6.0
cpe:2.3:o:redhat:enterprise_linux:6.0
Redhat
»
Enterprise Linux
»
Version:
7.0
cpe:2.3:o:redhat:enterprise_linux:7.0
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved