opensc-project records
5 published records for vendor opensc-project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-310 Cryptographic Issues2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-312 Cleartext Storage of Sensitive Information1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
30Monitor | CVE-2009-1603No exploit | src/tools/pkcs11-tool.c in pkcs11-tool in OpenSC 0.11.7, when used with unspecified third-party PKCS#11 modules, generates RSA keys with incopensc-project · opensc · CWE-312 | High7.5 | — | 1.1% | May 11, 2009 |
28Monitor | CVE-2010-4523No exploit | Multiple stack-based buffer overflows in libopensc in OpenSC 0.11.13 and earlier allow physically proximate attackers to execute arbitrary copensc-project · opensc · CWE-119 | High7.2 | — | 0.9% | Jan 7, 2011 |
26Monitor | CVE-2008-3972No exploit | pkcs15-tool in OpenSC before 0.11.6 does not apply security updates to a smart card unless the card's label matches the "OpenSC" string, whiopensc-project · opensc · CWE-264 | Medium6.6 | — | 0.4% | Sep 10, 2008 |
19Monitor | CVE-2008-2235No exploit | OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00) for the 5015 directory on smart cards and USB crypto tokensiemens · cardos · CWE-310 | Medium4.9 | — | 0.4% | Aug 1, 2008 |
8Monitor | CVE-2009-0368Proof of concept | OpenSC before 0.11.7 allows physically proximate attackers to bypass intended PIN requirements and read private data objects via a (1) low lopensc-project · opensc · CWE-310 | Low2.1 | — | 1.2% | Mar 2, 2009 |
- CVE-2009-160330Monitor
src/tools/pkcs11-tool.c in pkcs11-tool in OpenSC 0.11.7, when used with unspecified third-party PKCS#11 modules, generates RSA keys with inc
HighCVSS 7.5No exploitEPSS 1%opensc-project · openscMay 11, 2009
- CVE-2010-452328Monitor
Multiple stack-based buffer overflows in libopensc in OpenSC 0.11.13 and earlier allow physically proximate attackers to execute arbitrary c
HighCVSS 7.2No exploitEPSS 1%opensc-project · openscJan 7, 2011
- CVE-2008-397226Monitor
pkcs15-tool in OpenSC before 0.11.6 does not apply security updates to a smart card unless the card's label matches the "OpenSC" string, whi
MediumCVSS 6.6No exploitEPSS 0%opensc-project · openscSep 10, 2008
- CVE-2008-223519Monitor
OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00) for the 5015 directory on smart cards and USB crypto token
MediumCVSS 4.9No exploitEPSS 0%siemens · cardosAug 1, 2008
- CVE-2009-03688Monitor
OpenSC before 0.11.7 allows physically proximate attackers to bypass intended PIN requirements and read private data objects via a (1) low l
LowCVSS 2.1Proof of conceptEPSS 1%opensc-project · openscMar 2, 2009