Search CVE reports


Toggle filters

1 – 10 of 57 results


CVE-2025-66215

Medium priority
Needs evaluation

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow WRITE...

1 affected package

opensc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
opensc Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-66038

Medium priority
Needs evaluation

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sc_compacttlv_find_tag searches a compact-TLV buffer for a given tag. In compact-TLV, a single byte encodes the tag (high nibble) and value length...

1 affected package

opensc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
opensc Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-66037

Medium priority
Needs evaluation

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzz_pkcs15_reader harness causes OpenSC to perform an out-of-bounds heap read in the X.509/SPKI handling path....

1 affected package

opensc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
opensc Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-49010

Medium priority
Needs evaluation

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow write in GET...

1 affected package

opensc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
opensc Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-8443

Medium priority
Fixed

A heap-based buffer overflow vulnerability was found in the libopensc OpenPGP driver. A crafted USB device or smart card with malicious responses to the APDUs during the card enrollment process using the `pkcs15-init` tool may...

1 affected package

opensc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
opensc Fixed Fixed Fixed Not affected
Show less packages

CVE-2024-45620

Medium priority
Fixed

A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled...

1 affected package

opensc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
opensc Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-45619

Medium priority
Fixed

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When...

1 affected package

opensc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
opensc Fixed Fixed Not affected Not affected
Show less packages

CVE-2024-45618

Medium priority
Fixed

A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking of return...

1 affected package

opensc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
opensc Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-45617

Medium priority
Fixed

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response...

1 affected package

opensc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
opensc Fixed Fixed Fixed Not affected
Show less packages

CVE-2024-45616

Medium priority
Fixed

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. The...

1 affected package

opensc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
opensc Fixed Fixed Fixed Not affected
Show less packages