Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 16 Apr 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nasm netwide Assembler
|
|
| Weaknesses | CWE-787 | |
| CPEs | cpe:2.3:a:nasm:netwide_assembler:3.02:rc5:*:*:*:*:*:* | |
| Vendors & Products |
Nasm netwide Assembler
|
Tue, 14 Apr 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-122 |
Tue, 14 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-120 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 13 Apr 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-122 |
Fri, 10 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 10 Apr 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nasm
Nasm nasm |
|
| Vendors & Products |
Nasm
Nasm nasm |
Fri, 10 Apr 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A heap buffer overflow vulnerability exists in the Netwide Assembler (NASM) due to a lack of bounds checking in the obj_directive() function. This vulnerability can be exploited by a user assembling a malicious .asm file, potentially leading to heap memory corruption, denial of service (crash), and arbitrary code execution. | |
| Title | CVE-2026-6067 | |
| References |
|
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-04-10T14:58:07.818Z
Reserved: 2026-04-10T13:26:16.675Z
Link: CVE-2026-6067
Updated: 2026-04-10T14:57:45.406Z
Status : Analyzed
Published: 2026-04-10T14:16:38.620
Modified: 2026-04-23T18:34:03.253
Link: CVE-2026-6067
OpenCVE Enrichment
Updated: 2026-04-17T09:00:10Z