Opensc
Source repositories
CVEs (56)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-34193 | Hig | 0.49 | 7.5 | 0.01 | Aug 22, 2023 | Stack overflow vulnerability in OpenSC smart card middleware before 0.23 via crafted responses to APDUs. | ||
| CVE-2019-6502 | Hig | 0.49 | 7.5 | 0.02 | Jan 22, 2019 | sc_context_create in ctx.c in libopensc in OpenSC 0.19.0 has a memory leak, as demonstrated by a call from eidenv. | ||
| CVE-2009-1603 | Hig | 0.49 | 7.5 | 0.01 | May 11, 2009 | src/tools/pkcs11-tool.c in pkcs11-tool in OpenSC 0.11.7, when used with unspecified third-party PKCS#11 modules, generates RSA keys with incorrect public exponents, which allows attackers to read the cleartext form of messages that were intended to be encrypted. | ||
| CVE-2023-40660 | Med | 0.43 | 6.6 | 0.01 | Nov 6, 2023 | A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographic operations in other processes when an empty zero-length pin is passed. This issue poses a security risk, particularly for OS… | ||
| CVE-2013-1866 | Med | 0.40 | 6.1 | 0.00 | Jan 30, 2020 | OpenSC OpenSC.tokend has an Arbitrary File Creation/Overwrite Vulnerability | ||
| CVE-2025-13763 | Med | 0.37 | 5.7 | 0.00 | Apr 23, 2026 | Multiple uses of uninitialized variables were found in libopensc that may lead to information disclosure or application crash. An attack requires a crafted USB device or smart card that would present the system with specially crafted responses to the APDUs | ||
| CVE-2019-20792 | Med | 0.37 | 6.8 | 0.01 | Apr 29, 2020 | OpenSC before 0.20.0 has a double free in coolkey_free_private_data because coolkey_add_object in libopensc/card-coolkey.c lacks a uniqueness check. | ||
| CVE-2023-5992 | Med | 0.36 | 5.6 | 0.01 | Jan 31, 2024 | A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data. | ||
| CVE-2020-26571 | Med | 0.36 | 5.5 | 0.00 | Oct 6, 2020 | The gemsafe GPK smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in sc_pkcs15emu_gemsafeGPK_init. | ||
| CVE-2023-40661 | Med | 0.35 | 5.4 | 0.01 | Nov 6, 2023 | Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process using pkcs15-init when a user or administrator enrolls cards. To take advantage of these flaws, an attacker must have physical access to the computer system and… | ||
| CVE-2024-45619 | Med | 0.28 | 4.3 | 0.00 | Sep 3, 2024 | A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized… | ||
| CVE-2024-45620 | Low | 0.25 | 3.9 | 0.00 | Sep 3, 2024 | A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be… | ||
| CVE-2024-45618 | Low | 0.25 | 3.9 | 0.00 | Sep 3, 2024 | A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking of return values of functions leads to unexpected work with… | ||
| CVE-2024-45617 | Low | 0.25 | 3.9 | 0.00 | Sep 3, 2024 | A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking of return values of… | ||
| CVE-2024-45616 | Low | 0.25 | 3.9 | 0.00 | Sep 3, 2024 | A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. The following problems were caused by insufficient… | ||
| CVE-2024-45615 | Low | 0.25 | 3.9 | 0.00 | Sep 3, 2024 | A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. The problem is missing initialization of variables expected to be initialized (as arguments to other functions, etc.). | ||
| CVE-2024-8443 | Low | 0.19 | 2.9 | 0.00 | Sep 10, 2024 | A heap-based buffer overflow vulnerability was found in the libopensc OpenPGP driver. A crafted USB device or smart card with malicious responses to the APDUs during the card enrollment process using the `pkcs15-init` tool may lead to out-of-bound rights, possibly resulting in… | ||
| CVE-2026-40528 | Low | 0.18 | 3.8 | 0.00 | May 29, 2026 | OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_value() function in src/pkcs15init/profile.c that allows attackers to corrupt memory by supplying a crafted profile configuration file. During pkcs15-init… | ||
| CVE-2026-40510 | Low | 0.18 | 3.8 | 0.00 | May 29, 2026 | OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c that allows physically present attackers to trigger memory corruption by presenting a crafted PIV smart card or USB device… | ||
| CVE-2025-66215 | Low | 0.18 | 3.8 | 0.00 | Mar 30, 2026 | OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow WRITE in card-oberthur. The attack requires crafted USB device or… |
- risk 0.49cvss 7.5epss 0.01
Stack overflow vulnerability in OpenSC smart card middleware before 0.23 via crafted responses to APDUs.
- risk 0.49cvss 7.5epss 0.02
sc_context_create in ctx.c in libopensc in OpenSC 0.19.0 has a memory leak, as demonstrated by a call from eidenv.
- risk 0.49cvss 7.5epss 0.01
src/tools/pkcs11-tool.c in pkcs11-tool in OpenSC 0.11.7, when used with unspecified third-party PKCS#11 modules, generates RSA keys with incorrect public exponents, which allows attackers to read the cleartext form of messages that were intended to be encrypted.
- risk 0.43cvss 6.6epss 0.01
A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographic operations in other processes when an empty zero-length pin is passed. This issue poses a security risk, particularly for OS…
- risk 0.40cvss 6.1epss 0.00
OpenSC OpenSC.tokend has an Arbitrary File Creation/Overwrite Vulnerability
- risk 0.37cvss 5.7epss 0.00
Multiple uses of uninitialized variables were found in libopensc that may lead to information disclosure or application crash. An attack requires a crafted USB device or smart card that would present the system with specially crafted responses to the APDUs
- risk 0.37cvss 6.8epss 0.01
OpenSC before 0.20.0 has a double free in coolkey_free_private_data because coolkey_add_object in libopensc/card-coolkey.c lacks a uniqueness check.
- risk 0.36cvss 5.6epss 0.01
A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data.
- risk 0.36cvss 5.5epss 0.00
The gemsafe GPK smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in sc_pkcs15emu_gemsafeGPK_init.
- risk 0.35cvss 5.4epss 0.01
Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process using pkcs15-init when a user or administrator enrolls cards. To take advantage of these flaws, an attacker must have physical access to the computer system and…
- risk 0.28cvss 4.3epss 0.00
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized…
- risk 0.25cvss 3.9epss 0.00
A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be…
- risk 0.25cvss 3.9epss 0.00
A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking of return values of functions leads to unexpected work with…
- risk 0.25cvss 3.9epss 0.00
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking of return values of…
- risk 0.25cvss 3.9epss 0.00
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. The following problems were caused by insufficient…
- risk 0.25cvss 3.9epss 0.00
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. The problem is missing initialization of variables expected to be initialized (as arguments to other functions, etc.).
- risk 0.19cvss 2.9epss 0.00
A heap-based buffer overflow vulnerability was found in the libopensc OpenPGP driver. A crafted USB device or smart card with malicious responses to the APDUs during the card enrollment process using the `pkcs15-init` tool may lead to out-of-bound rights, possibly resulting in…
- risk 0.18cvss 3.8epss 0.00
OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_value() function in src/pkcs15init/profile.c that allows attackers to corrupt memory by supplying a crafted profile configuration file. During pkcs15-init…
- risk 0.18cvss 3.8epss 0.00
OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c that allows physically present attackers to trigger memory corruption by presenting a crafted PIV smart card or USB device…
- risk 0.18cvss 3.8epss 0.00
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow WRITE in card-oberthur. The attack requires crafted USB device or…
Page 1 of 3