Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
opensc-project vulnerabilities and exploits
(subscribe to this query)
6.6
CVSSv3
CVE-2018-16425
A double free when handling responses from an HSM Card in sc_pkcs15emu_sc_hsm_init in libopensc/pkcs15-sc-hsm.c in OpenSC prior to 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified...
Opensc Project Opensc
7.5
CVSSv3
CVE-2019-6502
sc_context_create in ctx.c in libopensc in OpenSC 0.19.0 has a memory leak, as demonstrated by a call from eidenv.
Opensc Project Opensc 0.19.0
5.5
CVSSv3
CVE-2019-19479
An issue exists in OpenSC up to and including 0.19.0 and 0.20.x up to and including 0.20.0-rc3. libopensc/card-setcos.c has an incorrect read operation during parsing of a SETCOS file attribute.
Opensc Project Opensc 0.20.0
Opensc Project Opensc
Debian Debian Linux 8.0
Debian Debian Linux 9.0
Fedoraproject Fedora 31
5.3
CVSSv3
CVE-2021-42782
Stack buffer overflow issues were found in Opensc before version 0.22.0 in various places that could potentially crash programs using the library.
Opensc Project Opensc
Fedoraproject Fedora 33
5.5
CVSSv3
CVE-2020-26572
The TCOS smart card software driver in OpenSC prior to 0.21.0-rc1 has a stack-based buffer overflow in tcos_decipher.
Opensc Project Opensc
Fedoraproject Fedora 33
Debian Debian Linux 9.0
5.5
CVSSv3
CVE-2020-26570
The Oberthur smart card software driver in OpenSC prior to 0.21.0-rc1 has a heap-based buffer overflow in sc_oberthur_read_file.
Opensc Project Opensc
Fedoraproject Fedora 33
Debian Debian Linux 9.0
5.5
CVSSv3
CVE-2020-26571
The gemsafe GPK smart card software driver in OpenSC prior to 0.21.0-rc1 has a stack-based buffer overflow in sc_pkcs15emu_gemsafeGPK_init.
Opensc Project Opensc
Debian Debian Linux 9.0
Fedoraproject Fedora 33
5.3
CVSSv3
CVE-2021-42780
A use after return issue was found in Opensc before version 0.22.0 in insert_pin function that could potentially crash programs using the library.
Opensc Project Opensc
Fedoraproject Fedora 33
Redhat Enterprise Linux 7.0
5.3
CVSSv3
CVE-2021-42781
Heap buffer overflow issues were found in Opensc before version 0.22.0 in pkcs15-oberthur.c that could potentially crash programs using the library.
Opensc Project Opensc
Fedoraproject Fedora 33
Redhat Enterprise Linux 7.0
6.6
CVSSv3
CVE-2023-40660
A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographic operations in other processes when an empty zero-length pin is passed. This issue poses a security risk, particularly for OS logo...
Opensc Project Opensc
Redhat Enterprise Linux 8.0
Redhat Enterprise Linux 9.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49223
CVE-2024-0044
information disclosure
CVE-2024-35753
HTML injection
CVE-2024-21306
CVE-2024-35733
SQL injection
CVE-2024-35732
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »