VYPR
Vendor

Opensc Project

Products
7
CVEs
60
Across products
78
Status
Private

Products

7

Recent CVEs

60
View all 60 CVEs →
  • CVE-2025-24032CriFeb 10, 2025
    risk 0.53cvss epss 0.01

    PAM-PKCS#11 is a Linux-PAM login module that allows a X.509 certificate based user login. Prior to version 0.6.13, if cert_policy is set to none (the default value), then pam_pkcs11 will only check if the user is capable of logging into the token. An attacker may create a…

  • CVE-2021-34193HigAug 22, 2023
    risk 0.49cvss 7.5epss 0.01

    Stack overflow vulnerability in OpenSC smart card middleware before 0.23 via crafted responses to APDUs.

  • CVE-2019-6502HigJan 22, 2019
    risk 0.49cvss 7.5epss 0.02

    sc_context_create in ctx.c in libopensc in OpenSC 0.19.0 has a memory leak, as demonstrated by a call from eidenv.

  • CVE-2009-1603HigMay 11, 2009
    risk 0.49cvss 7.5epss 0.01

    src/tools/pkcs11-tool.c in pkcs11-tool in OpenSC 0.11.7, when used with unspecified third-party PKCS#11 modules, generates RSA keys with incorrect public exponents, which allows attackers to read the cleartext form of messages that were intended to be encrypted.

  • CVE-2023-40660MedNov 6, 2023
    risk 0.43cvss 6.6epss 0.01

    A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographic operations in other processes when an empty zero-length pin is passed. This issue poses a security risk, particularly for OS…

  • CVE-2013-1866MedJan 30, 2020
    risk 0.40cvss 6.1epss 0.00

    OpenSC OpenSC.tokend has an Arbitrary File Creation/Overwrite Vulnerability

  • CVE-2025-13763MedApr 23, 2026
    risk 0.37cvss 5.7epss 0.00

    Multiple uses of uninitialized variables were found in libopensc that may lead to information disclosure or application crash. An attack requires a crafted USB device or smart card that would present the system with specially crafted responses to the APDUs

  • CVE-2025-24531MedJan 16, 2026
    risk 0.37cvss 6.7epss 0.00

    In OpenSC pam_pkcs11 before 0.6.13, pam_sm_authenticate() wrongly returns PAM_IGNORE in many error situations (such as an error triggered by a smartcard before login), allowing authentication bypass.

  • CVE-2019-20792MedApr 29, 2020
    risk 0.37cvss 6.8epss 0.01

    OpenSC before 0.20.0 has a double free in coolkey_free_private_data because coolkey_add_object in libopensc/card-coolkey.c lacks a uniqueness check.

  • CVE-2023-5992MedJan 31, 2024
    risk 0.36cvss 5.6epss 0.01

    A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data.

  • CVE-2020-26571MedOct 6, 2020
    risk 0.36cvss 5.5epss 0.00

    The gemsafe GPK smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in sc_pkcs15emu_gemsafeGPK_init.

  • CVE-2023-40661MedNov 6, 2023
    risk 0.35cvss 5.4epss 0.01

    Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process using pkcs15-init when a user or administrator enrolls cards. To take advantage of these flaws, an attacker must have physical access to the computer system and…

  • CVE-2025-24031MedFeb 10, 2025
    risk 0.33cvss epss 0.00

    PAM-PKCS#11 is a Linux-PAM login module that allows a X.509 certificate based user login. In versions 0.6.12 and prior, the pam_pkcs11 module segfaults when a user presses ctrl-c/ctrl-d when they are asked for a PIN. When a user enters no PIN at all, `pam_get_pwd` will never…

  • CVE-2024-45619MedSep 3, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized…

  • CVE-2026-10275MedJun 1, 2026
    risk 0.26cvss 5.0epss 0.00

    A flaw has been found in OpenSC up to 0.26.1. This affects the function test_kpgen_certwrite of the file src/tools/pkcs11-tool.c of the component pkcs11-tool Key Generation Module. This manipulation causes buffer overflow. The attack is possible to be carried out remotely. The…

  • CVE-2024-45620LowSep 3, 2024
    risk 0.25cvss 3.9epss 0.00

    A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be…

  • CVE-2024-45618LowSep 3, 2024
    risk 0.25cvss 3.9epss 0.00

    A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking of return values of functions leads to unexpected work with…

  • CVE-2024-45617LowSep 3, 2024
    risk 0.25cvss 3.9epss 0.00

    A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking of return values of…

  • CVE-2024-45616LowSep 3, 2024
    risk 0.25cvss 3.9epss 0.00

    A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. The following problems were caused by insufficient…

  • CVE-2024-45615LowSep 3, 2024
    risk 0.25cvss 3.9epss 0.00

    A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. The problem is missing initialization of variables expected to be initialized (as arguments to other functions, etc.).