Записи opensc-project
5 опубликованных записей вендора opensc-project.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-310 Cryptographic Issues2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-312 Cleartext Storage of Sensitive Information1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
5 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
30Наблюдать | CVE-2009-1603Эксплойта нет | src/tools/pkcs11-tool.c in pkcs11-tool in OpenSC 0.11.7, when used with unspecified third-party PKCS#11 modules, generates RSA keys with incopensc-project · opensc · CWE-312 | Высокая7,5 | — | 1,1 % | 11 мая 2009 г. |
28Наблюдать | CVE-2010-4523Эксплойта нет | Multiple stack-based buffer overflows in libopensc in OpenSC 0.11.13 and earlier allow physically proximate attackers to execute arbitrary copensc-project · opensc · CWE-119 | Высокая7,2 | — | 0,9 % | 7 янв. 2011 г. |
26Наблюдать | CVE-2008-3972Эксплойта нет | pkcs15-tool in OpenSC before 0.11.6 does not apply security updates to a smart card unless the card's label matches the "OpenSC" string, whiopensc-project · opensc · CWE-264 | Средняя6,6 | — | 0,4 % | 10 сент. 2008 г. |
19Наблюдать | CVE-2008-2235Эксплойта нет | OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00) for the 5015 directory on smart cards and USB crypto tokensiemens · cardos · CWE-310 | Средняя4,9 | — | 0,4 % | 1 авг. 2008 г. |
8Наблюдать | CVE-2009-0368Proof of concept | OpenSC before 0.11.7 allows physically proximate attackers to bypass intended PIN requirements and read private data objects via a (1) low lopensc-project · opensc · CWE-310 | Низкая2,1 | — | 1,2 % | 2 мар. 2009 г. |
- CVE-2009-160330Наблюдать
src/tools/pkcs11-tool.c in pkcs11-tool in OpenSC 0.11.7, when used with unspecified third-party PKCS#11 modules, generates RSA keys with inc
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %opensc-project · opensc11 мая 2009 г.
- CVE-2010-452328Наблюдать
Multiple stack-based buffer overflows in libopensc in OpenSC 0.11.13 and earlier allow physically proximate attackers to execute arbitrary c
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %opensc-project · opensc7 янв. 2011 г.
- CVE-2008-397226Наблюдать
pkcs15-tool in OpenSC before 0.11.6 does not apply security updates to a smart card unless the card's label matches the "OpenSC" string, whi
СредняяCVSS 6,6Эксплойта нетEPSS 0 %opensc-project · opensc10 сент. 2008 г.
- CVE-2008-223519Наблюдать
OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00) for the 5015 directory on smart cards and USB crypto token
СредняяCVSS 4,9Эксплойта нетEPSS 0 %siemens · cardos1 авг. 2008 г.
- CVE-2009-03688Наблюдать
OpenSC before 0.11.7 allows physically proximate attackers to bypass intended PIN requirements and read private data objects via a (1) low l
НизкаяCVSS 2,1Proof of conceptEPSS 1 %opensc-project · opensc2 мар. 2009 г.