Muscle maintains a focused vulnerability footprint centered on the PC/SC-Lite smart-card middleware library, a narrowly scoped but strategically positioned component in authentication and access-control systems. Its durable signal reflects memory-management complexity inherent to C-based middleware, with recurring issues around buffer-boundary violations and use-after-free conditions. Current exploitation status, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Muscle over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-0407MEDIUM Multiple buffer overflows in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 allow local users to g | Jun 18, 2010 | 6.8 | 22 | NO | NO |
CVE-2016-10109HIGH Use-after-free vulnerability in pcsc-lite before 1.8.20 allows a remote attackers to cause denial of service (crash) via a command that uses "cardsList" after the handle has been r | Feb 23, 2017 | 7.5 | 20 | NO | NO |
CVE-2009-4902MEDIUM Buffer overflow in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite 1.5.4 and earlier might allow local users to | Jun 18, 2010 | 6.8 | 20 | NO | NO |
CVE-2010-4531MEDIUM Stack-based buffer overflow in the ATRDecodeAtr function in the Answer-to-Reset (ATR) Handler (atrhandler.c) for pcscd in PCSC-Lite 1.5.3, and possibly other 1.5.x and 1.6.x versio | Jan 18, 2011 | 4.4 | 17 | NO | NO |
CVE-2010-4530MEDIUM Signedness error in ccid_serial.c in libccid in the USB Chip/Smart Card Interface Devices (CCID) driver, as used in pcscd in PCSC-Lite 1.5.3 and possibly other products, allows phy | Jan 18, 2011 | 4.4 | 17 | NO | NO |
The MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 might allow local users to cause a denial of servic | Jun 18, 2010 | 2.1 | 13 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Muscle.
Media articles that mention a CVE ID that affects a product developed by Muscle — matched by CVE ID, not by vendor name.