Search CVE reports
11 – 20 of 53 results
CVE-2023-40661
Medium prioritySome fixes available 2 of 4
Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process using pkcs15-init when a user or administrator enrolls cards. To take advantage of these flaws, an attacker...
1 affected package
opensc
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
opensc | Not affected | Fixed | Fixed | Not affected | Not affected |
CVE-2023-40660
Medium prioritySome fixes available 2 of 4
A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographic operations in other processes when an empty zero-length pin is passed....
1 affected package
opensc
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
opensc | Not affected | Fixed | Fixed | Not affected | Not affected |
CVE-2021-34193
Medium priorityStack overflow vulnerability in OpenSC smart card middleware before 0.23 via crafted responses to APDUs.
1 affected package
opensc
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
opensc | Not affected | Not affected | Not affected | Not affected | Not affected |
CVE-2023-2977
Medium prioritySome fixes available 4 of 7
A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can supply a smart card package with malformed ASN1 context....
1 affected package
opensc
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
opensc | Not affected | Fixed | Fixed | Fixed | Fixed |
CVE-2022-0497
Medium priorityA vulnerbiility was found in Openscad, where a .scad file with no trailing newline could cause an out-of-bounds read during parsing of annotations.
1 affected package
openscad
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
openscad | Not affected | Needs evaluation | Needs evaluation | — | Needs evaluation |
CVE-2022-0496
Medium priorityA vulnerbiility was found in Openscad, where a DXF-format drawing with particular (not necessarily malformed!) properties may cause an out-of-bounds memory access when imported using import().
1 affected package
openscad
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
openscad | Not affected | Needs evaluation | Needs evaluation | — | Needs evaluation |
CVE-2021-42782
Medium prioritySome fixes available 1 of 8
Stack buffer overflow issues were found in Opensc before version 0.22.0 in various places that could potentially crash programs using the library.
1 affected package
opensc
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
opensc | Not affected | Not affected | Fixed | Ignored | Ignored |
CVE-2021-42781
Medium priorityHeap buffer overflow issues were found in Opensc before version 0.22.0 in pkcs15-oberthur.c that could potentially crash programs using the library.
1 affected package
opensc
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
opensc | Not affected | Not affected | Not affected | Not affected | Not affected |
CVE-2021-42780
Medium prioritySome fixes available 3 of 8
A use after return issue was found in Opensc before version 0.22.0 in insert_pin function that could potentially crash programs using the library.
1 affected package
opensc
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
opensc | Not affected | Not affected | Fixed | Fixed | Fixed |
CVE-2021-42779
Medium priorityA heap use after free issue was found in Opensc before version 0.22.0 in sc_file_valid.
1 affected package
opensc
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
opensc | Not affected | Not affected | Ignored | Ignored | Ignored |