Search CVE reports


Toggle filters

11 – 20 of 57 results


CVE-2024-45615

Medium priority
Fixed

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. The problem is missing initialization of variables expected to be initialized (as arguments to other functions, etc.).

1 affected package

opensc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
opensc Fixed Fixed Fixed Not affected
Show less packages

CVE-2024-1454

Medium priority
Ignored

The use-after-free vulnerability was found in the AuthentIC driver in OpenSC packages, occuring in the card enrolment process using pkcs15-init when a user or administrator enrols or modifies cards. An attacker must have physical...

1 affected package

opensc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
opensc Not affected Not affected Not affected Not affected
Show less packages

CVE-2023-5992

Medium priority

Some fixes available 1 of 2

A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data.

1 affected package

opensc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
opensc Not affected Fixed Not affected Not affected
Show less packages

CVE-2023-4535

Medium priority
Ignored

An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires an attacker to have physical access to the computer and a specially...

1 affected package

opensc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
opensc Not affected Not affected Not affected Not affected
Show less packages

CVE-2023-40661

Medium priority

Some fixes available 2 of 4

Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process using pkcs15-init when a user or administrator enrolls cards. To take advantage of these flaws, an attacker...

1 affected package

opensc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
opensc Not affected Fixed Fixed Not affected
Show less packages

CVE-2023-40660

Medium priority

Some fixes available 2 of 4

A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographic operations in other processes when an empty zero-length pin is passed....

1 affected package

opensc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
opensc Not affected Fixed Fixed Not affected
Show less packages

CVE-2021-34193

Medium priority
Ignored

Stack overflow vulnerability in OpenSC smart card middleware before 0.23 via crafted responses to APDUs.

1 affected package

opensc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
opensc Not affected Not affected Not affected Not affected
Show less packages

CVE-2023-2977

Medium priority

Some fixes available 4 of 7

A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can supply a smart card package with malformed ASN1 context....

1 affected package

opensc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
opensc Not affected Fixed Fixed Fixed
Show less packages

CVE-2022-0497

Medium priority
Needs evaluation

A vulnerbiility was found in Openscad, where a .scad file with no trailing newline could cause an out-of-bounds read during parsing of annotations.

1 affected package

openscad

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openscad Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2022-0496

Medium priority
Needs evaluation

A vulnerbiility was found in Openscad, where a DXF-format drawing with particular (not necessarily malformed!) properties may cause an out-of-bounds memory access when imported using import().

1 affected package

openscad

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openscad Not affected Needs evaluation Needs evaluation
Show less packages