VendorsOpenSC Projectopenscall versions
Vulnerabilities

OpenSC Project OpenSC

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

50CVEs
CVE-2026-40528
OpenSC < 0.27.0 Buffer Overrun in do_key_value() via profile.c
Published 2026-05-29 · Analyzed
7.8EPSS 0.001
CVE-2019-6502
sc_context_create in ctx.c in libopensc in OpenSC 0.19.0 has a memory leak, as demonstrated by a call from eidenv.
Published 2019-01-22 · Modified
7.5EPSS 0.022
CVE-2019-16058
An issue was discovered in the pam_p11 component 0.2.0 and 0.3.0 for OpenSC. If a smart card creates a signature with a length longer than 256 bytes, this triggers a buffer overflow. This may be the case for RSA keys with 4096 bits depending on the signature scheme.
Published 2019-09-06 · Modified
7.5EPSS 0.015
CVE-2021-34193
Stack overflow vulnerability in OpenSC smart card middleware before 0.23 via crafted responses to APDUs.
Published 2023-08-22 · Modified
7.5EPSS 0.014
CVE-2023-2977
A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can supply a smart card package with malformed ASN1 context. The cardos_have_verifyrc_package function scans the ASN1 buffer for 2 tags, where remaining length is wrongly caculated due to moved starting pointer. This leads to possible heap-based buffer oob read. In cases where ASAN is enabled while compiling this causes a crash. Further info leak or more damage is possible.
Published 2023-06-01 · Modified
7.1EPSS 0.003
CVE-2018-16391
Several buffer overflows when handling responses from a Muscle Card in muscle_list_files in libopensc/card-muscle.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
Published 2018-09-03 · Modified
6.8EPSS 0.007
CVE-2019-20792
OpenSC before 0.20.0 has a double free in coolkey_free_private_data because coolkey_add_object in libopensc/card-coolkey.c lacks a uniqueness check.
Published 2020-04-29 · Modified
6.8EPSS 0.007
CVE-2018-16392
Several buffer overflows when handling responses from a TCOS Card in tcos_select_file in libopensc/card-tcos.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
Published 2018-09-03 · Modified
6.8EPSS 0.006
CVE-2018-16393
Several buffer overflows when handling responses from a Gemsafe V1 Smartcard in gemsafe_get_cert_len in libopensc/pkcs15-gemsafeV1.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
Published 2018-09-03 · Modified
6.8EPSS 0.006
CVE-2026-40510
OpenSC < 0.27.0-rc1 Stack Buffer Overflow via piv_process_history() in card-piv.c
Published 2026-05-29 · Analyzed
6.8EPSS 0.003
CVE-2025-66038
OpenSC: `sc_compacttlv_find_tag` can return out-of-bounds pointers
Published 2026-03-30 · Analyzed
6.8EPSS 0.003
CVE-2025-66037
OpenSC: Out of Bounds vulnerability
Published 2026-03-30 · Analyzed
6.8EPSS 0.003
CVE-2025-66215
OpenSC: Stack-buffer-overflow WRITE in card-oberthur
Published 2026-03-30 · Analyzed
6.8EPSS 0.002
CVE-2025-49010
OpenSC: Stack-buffer-overflow WRITE in GET RESPONSE
Published 2026-03-30 · Analyzed
6.8EPSS 0.001
CVE-2023-40660
Opensc: potential pin bypass when card tracks its own login state
Published 2023-11-06 · Modified
6.6EPSS 0.009
CVE-2018-16422
A single byte buffer overflow when handling responses from an esteid Card in sc_pkcs15emu_esteid_init in libopensc/pkcs15-esteid.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
Published 2018-09-04 · Modified
6.6EPSS 0.007
CVE-2018-16421
Several buffer overflows when handling responses from a CAC Card in cac_get_serial_nr_from_CUID in libopensc/card-cac.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
Published 2018-09-04 · Modified
6.6EPSS 0.007
CVE-2018-16418
A buffer overflow when handling string concatenation in util_acl_to_str in tools/util.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
Published 2018-09-04 · Modified
6.6EPSS 0.007
CVE-2018-16419
Several buffer overflows when handling responses from a Cryptoflex card in read_public_key in tools/cryptoflex-tool.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
Published 2018-09-04 · Modified
6.6EPSS 0.007
CVE-2018-16420
Several buffer overflows when handling responses from an ePass 2003 Card in decrypt_response in libopensc/card-epass2003.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
Published 2018-09-04 · Modified
6.6EPSS 0.007
CVE-2018-16423
A double free when handling responses from a smartcard in sc_file_set_sec_attr in libopensc/sc.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
Published 2018-09-04 · Modified
6.6EPSS 0.007
CVE-2018-16425
A double free when handling responses from an HSM Card in sc_pkcs15emu_sc_hsm_init in libopensc/pkcs15-sc-hsm.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
Published 2018-09-04 · Modified
6.6EPSS 0.007
CVE-2018-16424
A double free when handling responses in read_file in tools/egk-tool.c (aka the eGK card tool) in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.
Published 2018-09-04 · Modified
6.6EPSS 0.007
CVE-2023-40661
Opensc: multiple memory issues with pkcs15-init (enrollment tool)
Published 2023-11-06 · Modified
6.4EPSS 0.012
CVE-2019-15945
OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Bitstring in decode_bit_string in libopensc/asn1.c.
Published 2019-09-05 · Modified
6.4EPSS 0.004
CVE-2019-15946
OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Octet string in asn1_decode_entry in libopensc/asn1.c.
Published 2019-09-05 · Modified
6.4EPSS 0.004
CVE-2013-1866
OpenSC OpenSC.tokend has an Arbitrary File Creation/Overwrite Vulnerability
Published 2020-01-30 · Modified
6.3EPSS 0.004
CVE-2023-5992
Opensc: side-channel leaks while stripping encryption pkcs#1 padding
Published 2024-01-31 · Modified
5.9EPSS 0.012
CVE-2020-26571
The gemsafe GPK smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in sc_pkcs15emu_gemsafeGPK_init.
Published 2020-10-06 · Modified
5.5EPSS 0.004
CVE-2019-19479
An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-setcos.c has an incorrect read operation during parsing of a SETCOS file attribute.
Published 2019-12-01 · Modified
5.5EPSS 0.004
CVE-2020-26570
The Oberthur smart card software driver in OpenSC before 0.21.0-rc1 has a heap-based buffer overflow in sc_oberthur_read_file.
Published 2020-10-06 · Modified
5.5EPSS 0.004
CVE-2020-26572
The TCOS smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in tcos_decipher.
Published 2020-10-06 · Modified
5.5EPSS 0.004
CVE-2021-42781
Heap buffer overflow issues were found in Opensc before version 0.22.0 in pkcs15-oberthur.c that could potentially crash programs using the library.
Published 2022-04-18 · Modified
5.3EPSS 0.029
CVE-2021-42782
Stack buffer overflow issues were found in Opensc before version 0.22.0 in various places that could potentially crash programs using the library.
Published 2022-04-18 · Modified
5.3EPSS 0.028
CVE-2021-42780
A use after return issue was found in Opensc before version 0.22.0 in insert_pin function that could potentially crash programs using the library.
Published 2022-04-18 · Modified
5.3EPSS 0.021
CVE-2021-42778
A heap double free issue was found in Opensc before version 0.22.0 in sc_pkcs15_free_tokeninfo.
Published 2022-04-18 · Modified
5.3EPSS 0.021
CVE-2021-42779
A heap use after free issue was found in Opensc before version 0.22.0 in sc_file_valid.
Published 2022-04-18 · Modified
5.3EPSS 0.021
CVE-2019-19480
An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/pkcs15-prkey.c has an incorrect free operation in sc_pkcs15_decode_prkdf_entry.
Published 2019-12-01 · Modified
4.6EPSS 0.006
CVE-2019-19481
An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-cac1.c mishandles buffer limits for CAC certificates.
Published 2019-12-01 · Modified
4.6EPSS 0.002
CVE-2023-4535
Opensc: out-of-bounds read in myeid driver handling encryption using symmetric keys
Published 2023-11-06 · Modified
4.5EPSS 0.005
1 / 2Next →