VendorsopenCryptoki Projectopencryptokiall versions
Vulnerabilities

openCryptoki Project openCryptoki

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2026-23893
openCryptoki has improper link resolution before file access (link following)
Published 2026-01-22 · Analyzed
6.8EPSS 0.002
CVE-2026-40253
openCryptoki: Memory safety vulnerabilities in BER/DER decoders in asn1.c
Published 2026-04-16 · Analyzed
6.8EPSS 0.002
CVE-2026-22791
openCryptoki incorrectly calculates the buffer size in C_WrapKey with CKM_ECDH_AES_KEY_WRAP
Published 2026-01-13 · Analyzed
6.6EPSS 0.003
CVE-2012-4455
openCryptoki 2.4.1 allows local users to create or set world-writable permissions on arbitrary files via a symlink attack on the (1) LCK..opencryptoki or (2) LCK..opencryptoki_stdll file in /var/lock/.
Published 2012-10-10 · Modified
6.2EPSS 0.004
CVE-2024-0914
Opencryptoki: timing side-channel in handling of rsa pkcs#1 v1.5 padded ciphertexts (marvin)
Published 2024-01-31 · Modified
5.9EPSS 0.009
CVE-2021-3798
A flaw was found in openCryptoki. The openCryptoki Soft token does not check if an EC key is valid when an EC key is created via C_CreateObject, nor when C_DeriveKey is used with ECDH public data. This may allow a malicious user to extract the private key by performing an invalid curve attack.
Published 2022-08-23 · Modified
5.5EPSS 0.003
CVE-2012-4454
openCryptoki before 2.4.1, when using spinlocks, allows local users to create or set world-writable permissions on arbitrary files via a symlink attack on the (1) .pkapi_xpk or (2) .pkcs11spinloc file in /tmp.
Published 2012-10-10 · Modified
2.9EPSS 0.010