Vulnerabilities > Opensc Project > Opensc > High

DATE CVE VULNERABILITY TITLE RISK
2023-08-22 CVE-2021-34193 Out-of-bounds Write vulnerability in Opensc Project Opensc
Stack overflow vulnerability in OpenSC smart card middleware before 0.23 via crafted responses to APDUs.
network
low complexity
opensc-project CWE-787
7.5
2023-06-01 CVE-2023-2977 Out-of-bounds Read vulnerability in multiple products
A vulnerbility was found in OpenSC.
local
low complexity
opensc-project redhat CWE-125
7.1
2019-01-22 CVE-2019-6502 Memory Leak vulnerability in Opensc Project Opensc 0.19.0
sc_context_create in ctx.c in libopensc in OpenSC 0.19.0 has a memory leak, as demonstrated by a call from eidenv.
network
low complexity
opensc-project CWE-401
7.5
2011-01-07 CVE-2010-4523 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Opensc-Project Opensc
Multiple stack-based buffer overflows in libopensc in OpenSC 0.11.13 and earlier allow physically proximate attackers to execute arbitrary code via a long serial-number field on a smart card, related to (1) card-acos5.c, (2) card-atrust-acos.c, and (3) card-starcos.c.
local
low complexity
opensc-project CWE-119
7.2
2009-05-11 CVE-2009-1603 Cleartext Storage of Sensitive Information vulnerability in multiple products
src/tools/pkcs11-tool.c in pkcs11-tool in OpenSC 0.11.7, when used with unspecified third-party PKCS#11 modules, generates RSA keys with incorrect public exponents, which allows attackers to read the cleartext form of messages that were intended to be encrypted.
network
low complexity
opensc-project fedoraproject CWE-312
7.5