CVE-2018-16999: Nasm Netwide Assembler

Medium severity, CVSS 5.5. EPSS: 1.1% chance of exploitation in the next 30 days.

Netwide Assembler (NASM) 2.14rc15 has an invalid memory write (segmentation fault) in expand_smacro in preproc.c, which allows attackers to cause a denial of service via a crafted input file.

Affected products

  • Nasm Netwide Assembler: version 12.14 only

Published 2018-09-13. Last modified 2026-06-17.