VendorsOpenSC Projectopenscall versions
Vulnerabilities

OpenSC Project OpenSC

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

50CVEs
CVE-2018-16426
Endless recursion when handling responses from an IAS-ECC card in iasecc_select_file in libopensc/card-iasecc.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to hang or crash the opensc library using programs.
Published 2018-09-04 · Modified
4.3EPSS 0.006
CVE-2018-16427
Various out of bounds reads when handling responses in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to potentially crash the opensc library using programs.
Published 2018-09-04 · Modified
4.3EPSS 0.005
CVE-2024-45619
Libopensc: incorrect handling length of buffers or files in libopensc
Published 2024-09-03 · Modified
4.3EPSS 0.003
CVE-2024-45616
Libopensc: uninitialized values after incorrect check or usage of apdu response values in libopensc
Published 2024-09-03 · Modified
3.9EPSS 0.004
CVE-2024-45615
Libopensc: pkcs15init: usage of uninitialized values in libopensc and pkcs15init
Published 2024-09-03 · Modified
3.9EPSS 0.004
CVE-2024-45620
Libopensc: incorrect handling of the length of buffers or files in pkcs15init
Published 2024-09-03 · Modified
3.9EPSS 0.003
CVE-2024-45618
Libopensc: uninitialized values after incorrect or missing checking return values of functions in pkcs15init
Published 2024-09-03 · Modified
3.9EPSS 0.003
CVE-2024-45617
Libopensc: uninitialized values after incorrect or missing checking return values of functions in libopensc
Published 2024-09-03 · Modified
3.9EPSS 0.003
CVE-2024-1454
Opensc: memory use after free in authentic driver when updating token info
Published 2024-02-12 · Modified
3.4EPSS 0.004
CVE-2024-8443
Libopensc: heap buffer overflow in openpgp driver when generating key
Published 2024-09-10 · Modified
2.9EPSS 0.003
← Prev2 / 2