Vulnerability index

Browse CVEs

22 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Opensc HIGH 7.8
CVE-2026-40528

OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_value() function in src/pkcs15ini…

Fix: 0.27.0+
Fix from $1,950 2026-05-29
Opensc MEDIUM 6.8
CVE-2026-40510

OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.…

Fix: 0.27.0+
Fix from $1,600 2026-05-29
Opensc MEDIUM 6.8
CVE-2025-66037

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzz_pkcs15_reader harness causes O…

Fix: 0.27.0+
Fix from $1,600 2026-03-30
Opensc MEDIUM 6.8
CVE-2025-66038

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sc_compacttlv_find_tag searches a compact-TLV buffer for a given t…

Fix: 0.27.0+
Fix from $1,600 2026-03-30
Opensc MEDIUM 6.8
CVE-2025-66215

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user …

Fix: 0.27.0+
Fix from $1,600 2026-03-30
Opensc MEDIUM 6.8
CVE-2025-49010

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user …

Fix: 0.27.0+
Fix from $1,600 2026-03-30
Opensc HIGH 7.5
CVE-2021-34193

Stack overflow vulnerability in OpenSC smart card middleware before 0.23 via crafted responses to APDUs.

Fix: 0.22.0+
Fix from $1,950 2023-08-22
Opensc MEDIUM 6.8
CVE-2019-20792

OpenSC before 0.20.0 has a double free in coolkey_free_private_data because coolkey_add_object in libopensc/card-coolkey.c lacks a uniqueness check.

Fix: 0.20.0+
Fix from $1,600 2020-04-29
Opensc MEDIUM 6.1
CVE-2013-1866

OpenSC OpenSC.tokend has an Arbitrary File Creation/Overwrite Vulnerability

Fix: 0.13.0+
Fix from $1,600 2020-01-30
Opensc HIGH 7.5
CVE-2019-16058

An issue was discovered in the pam_p11 component 0.2.0 and 0.3.0 for OpenSC. If a smart card creates a signature with a length longer than 256 bytes,…

Patch available
Fix from $1,950 2019-09-06
Opensc HIGH 7.5
CVE-2019-6502

sc_context_create in ctx.c in libopensc in OpenSC 0.19.0 has a memory leak, as demonstrated by a call from eidenv.

No fix yet
Fix from $1,950 2019-01-22
Opensc MEDIUM 6.6
CVE-2018-16424

A double free when handling responses in read_file in tools/egk-tool.c (aka the eGK card tool) in OpenSC before 0.19.0-rc1 could be used by attackers…

Fix: after 0.18.0
Fix from $1,600 2018-09-04
Opensc MEDIUM 6.6
CVE-2018-16425

A double free when handling responses from an HSM Card in sc_pkcs15emu_sc_hsm_init in libopensc/pkcs15-sc-hsm.c in OpenSC before 0.19.0-rc1 could be …

Fix: after 0.18.0
Fix from $1,600 2018-09-04
Opensc MEDIUM 6.6
CVE-2018-16418

A buffer overflow when handling string concatenation in util_acl_to_str in tools/util.c in OpenSC before 0.19.0-rc1 could be used by attackers able t…

Fix: after 0.18.0
Fix from $1,600 2018-09-04
Opensc MEDIUM 6.6
CVE-2018-16419

Several buffer overflows when handling responses from a Cryptoflex card in read_public_key in tools/cryptoflex-tool.c in OpenSC before 0.19.0-rc1 cou…

Fix: after 0.18.0
Fix from $1,600 2018-09-04
Opensc MEDIUM 6.6
CVE-2018-16420

Several buffer overflows when handling responses from an ePass 2003 Card in decrypt_response in libopensc/card-epass2003.c in OpenSC before 0.19.0-rc…

Fix: after 0.18.0
Fix from $1,600 2018-09-04
Opensc MEDIUM 6.6
CVE-2018-16421

Several buffer overflows when handling responses from a CAC Card in cac_get_serial_nr_from_CUID in libopensc/card-cac.c in OpenSC before 0.19.0-rc1 c…

Fix: after 0.18.0
Fix from $1,600 2018-09-04
Opensc MEDIUM 6.6
CVE-2018-16422

A single byte buffer overflow when handling responses from an esteid Card in sc_pkcs15emu_esteid_init in libopensc/pkcs15-esteid.c in OpenSC before 0…

Fix: after 0.18.0
Fix from $1,600 2018-09-04
Opensc MEDIUM 6.6
CVE-2018-16423

A double free when handling responses from a smartcard in sc_file_set_sec_attr in libopensc/sc.c in OpenSC before 0.19.0-rc1 could be used by attacke…

Fix: after 0.18.0
Fix from $1,600 2018-09-04
Opensc MEDIUM 6.8
CVE-2018-16391

Several buffer overflows when handling responses from a Muscle Card in muscle_list_files in libopensc/card-muscle.c in OpenSC before 0.19.0-rc1 could…

Fix: after 0.18.0
Fix from $1,600 2018-09-03
Opensc MEDIUM 6.8
CVE-2018-16392

Several buffer overflows when handling responses from a TCOS Card in tcos_select_file in libopensc/card-tcos.c in OpenSC before 0.19.0-rc1 could be u…

Fix: after 0.18.0
Fix from $1,600 2018-09-03
Opensc MEDIUM 6.8
CVE-2018-16393

Several buffer overflows when handling responses from a Gemsafe V1 Smartcard in gemsafe_get_cert_len in libopensc/pkcs15-gemsafeV1.c in OpenSC before…

Fix: after 0.18.0
Fix from $1,600 2018-09-03