Search CVE reports


Toggle filters

11 – 20 of 53 results


CVE-2023-40661

Medium priority

Some fixes available 2 of 4

Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process using pkcs15-init when a user or administrator enrolls cards. To take advantage of these flaws, an attacker...

1 affected package

opensc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
opensc Not affected Fixed Fixed Not affected Not affected
Show less packages

CVE-2023-40660

Medium priority

Some fixes available 2 of 4

A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographic operations in other processes when an empty zero-length pin is passed....

1 affected package

opensc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
opensc Not affected Fixed Fixed Not affected Not affected
Show less packages

CVE-2021-34193

Medium priority
Ignored

Stack overflow vulnerability in OpenSC smart card middleware before 0.23 via crafted responses to APDUs.

1 affected package

opensc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
opensc Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2023-2977

Medium priority

Some fixes available 4 of 7

A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can supply a smart card package with malformed ASN1 context....

1 affected package

opensc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
opensc Not affected Fixed Fixed Fixed Fixed
Show less packages

CVE-2022-0497

Medium priority
Needs evaluation

A vulnerbiility was found in Openscad, where a .scad file with no trailing newline could cause an out-of-bounds read during parsing of annotations.

1 affected package

openscad

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
openscad Not affected Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-0496

Medium priority
Needs evaluation

A vulnerbiility was found in Openscad, where a DXF-format drawing with particular (not necessarily malformed!) properties may cause an out-of-bounds memory access when imported using import().

1 affected package

openscad

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
openscad Not affected Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-42782

Medium priority

Some fixes available 1 of 8

Stack buffer overflow issues were found in Opensc before version 0.22.0 in various places that could potentially crash programs using the library.

1 affected package

opensc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
opensc Not affected Not affected Fixed Ignored Ignored
Show less packages

CVE-2021-42781

Medium priority
Ignored

Heap buffer overflow issues were found in Opensc before version 0.22.0 in pkcs15-oberthur.c that could potentially crash programs using the library.

1 affected package

opensc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
opensc Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2021-42780

Medium priority

Some fixes available 3 of 8

A use after return issue was found in Opensc before version 0.22.0 in insert_pin function that could potentially crash programs using the library.

1 affected package

opensc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
opensc Not affected Not affected Fixed Fixed Fixed
Show less packages

CVE-2021-42779

Medium priority
Ignored

A heap use after free issue was found in Opensc before version 0.22.0 in sc_file_valid.

1 affected package

opensc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
opensc Not affected Not affected Ignored Ignored Ignored
Show less packages