Skip to main content

Vendor/product archive

opensc_project / opensc CVEs

Beta · best-effort

50 CVEs tagged to opensc_project / opensc0 Critical, 4 High, 33 Medium, 13 Low, 0 Unrated.

CVE-2026-40528

Published May 29, 2026

OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_value() function in src/pkcs15init/profile.c that allows attack…

CVSS 1.0 · Low
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-40510

Published May 29, 2026

OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c that allows physically prese…

CVSS 1.0 · Low
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2025-66215

Published Mar 30, 2026

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token…

CVSS 3.8 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-66038

Published Mar 30, 2026

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sc_compacttlv_find_tag searches a compact-TLV buffer for a given tag. In compact-TLV, a single b…

CVSS 3.9 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-66037

Published Mar 30, 2026

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzz_pkcs15_reader harness causes OpenSC to perform an out-of-bou…

CVSS 3.9 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-49010

Published Mar 30, 2026

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token…

CVSS 3.8 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-34193

Published Aug 22, 2023

Stack overflow vulnerability in OpenSC smart card middleware before 0.23 via crafted responses to APDUs.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 50 CVEsPage 1 of 2