CVE-2023-40661
- EPSS 0.31%
- Published 06.11.2023 17:15:11
- Last modified 21.11.2024 08:19:55
Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process using pkcs15-init when a user or administrator enrolls cards. To take advantage of these flaws, an attacker must have physical acce...
CVE-2023-40660
- EPSS 0.03%
- Published 06.11.2023 17:15:11
- Last modified 04.12.2024 08:15:04
A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographic operations in other processes when an empty zero-length pin is passed. This issue poses a security ...
CVE-2021-34193
- EPSS 0.41%
- Published 22.08.2023 19:16:20
- Last modified 21.11.2024 06:10:00
Stack overflow vulnerability in OpenSC smart card middleware before 0.23 via crafted responses to APDUs.
CVE-2023-2977
- EPSS 0.02%
- Published 01.06.2023 01:15:17
- Last modified 09.01.2025 18:15:25
A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can supply a smart card package with malformed ASN1 context. The cardos_have_verifyrc_package function sc...
CVE-2021-42782
- EPSS 0.08%
- Published 18.04.2022 17:15:16
- Last modified 21.11.2024 06:28:09
Stack buffer overflow issues were found in Opensc before version 0.22.0 in various places that could potentially crash programs using the library.
CVE-2021-42781
- EPSS 0.08%
- Published 18.04.2022 17:15:16
- Last modified 21.11.2024 06:28:09
Heap buffer overflow issues were found in Opensc before version 0.22.0 in pkcs15-oberthur.c that could potentially crash programs using the library.
CVE-2021-42780
- EPSS 0.05%
- Published 18.04.2022 17:15:16
- Last modified 21.11.2024 06:28:09
A use after return issue was found in Opensc before version 0.22.0 in insert_pin function that could potentially crash programs using the library.
CVE-2021-42779
- EPSS 0.05%
- Published 18.04.2022 17:15:16
- Last modified 21.11.2024 06:28:09
A heap use after free issue was found in Opensc before version 0.22.0 in sc_file_valid.
CVE-2021-42778
- EPSS 0.35%
- Published 18.04.2022 17:15:16
- Last modified 21.11.2024 06:28:09
A heap double free issue was found in Opensc before version 0.22.0 in sc_pkcs15_free_tokeninfo.
CVE-2020-26572
- EPSS 0.05%
- Published 06.10.2020 02:15:13
- Last modified 21.11.2024 05:20:06
The TCOS smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in tcos_decipher.