Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Opensc Project

First CVE: Sep 3, 2018Active for: 8 yearsTotal CVEs: 55
20.0
VTI Score
Low

The OpenSC Project maintains a cryptographic middleware library that provides access to smart cards and hardware security tokens across multiple platforms, a narrow product scope but one embedded in identity and authentication infrastructure where supply-chain reach matters substantially. The vulnerability footprint concentrates in a single, widely used implementation and recurs through a consistent pattern of memory-safety issues: buffer overflows, out-of-bounds reads and writes, and double-free conditions that are characteristic of C-based cryptographic parsers handling untrusted card data. These weakness classes reflect the low-level nature of smart-card communication and the parsing complexity inherent to supporting multiple card standards and protocols. Defenders should inventory products and systems that link this library, as remediation typically depends on downstream vendors rebuilding and shipping updates; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
55
Total CVEs
More Total CVEs than 99% of tracked vendors
5.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Opensc Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 1, 2008
17 years ago
Most Recent CVE
May 29, 2026
55 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (55 CVEs).

55 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-40528HIGH
OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_value() function in src/pkcs15init/profile.c that allows attacke
May 29, 20267.829NONO
CVE-2026-40510MEDIUM
OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c that allows physically presen
May 29, 20266.827NONO
CVE-2025-66037MEDIUM
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzz_pkcs15_reader harness causes OpenSC to perform an out-of-boun
Mar 30, 20266.825NONO
CVE-2025-49010MEDIUM
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token c
Mar 30, 20266.825NONO
CVE-2025-66215MEDIUM
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token c
Mar 30, 20266.824NONO
CVE-2025-66038MEDIUM
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sc_compacttlv_find_tag searches a compact-TLV buffer for a given tag. In compact-TLV, a single by
Mar 30, 20266.824NONO
CVE-2019-20792MEDIUM
OpenSC before 0.20.0 has a double free in coolkey_free_private_data because coolkey_add_object in libopensc/card-coolkey.c lacks a uniqueness check.
Apr 29, 20206.823NONO
CVE-2019-16058HIGH
An issue was discovered in the pam_p11 component 0.2.0 and 0.3.0 for OpenSC. If a smart card creates a signature with a length longer than 256 bytes, this triggers a buffer overflo
Sep 6, 20197.523NONO
CVE-2018-16393MEDIUM
Several buffer overflows when handling responses from a Gemsafe V1 Smartcard in gemsafe_get_cert_len in libopensc/pkcs15-gemsafeV1.c in OpenSC before 0.19.0-rc1 could be used by at
Sep 3, 20186.823NONO
CVE-2018-16392MEDIUM
Several buffer overflows when handling responses from a TCOS Card in tcos_select_file in libopensc/card-tcos.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply
Sep 3, 20186.823NONO
View all 55 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products55 CVEs
16%
71%
13%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local6 (10.9%)
Network10 (18.2%)
Unknown4 (7.3%)
Physical35 (63.6%)
Adjacent Network0 (0.0%)
Attack Complexity
Low40 (72.7%)
High11 (20.0%)
Unknown4 (7.3%)
User Interaction
None45 (81.8%)
Unknown4 (7.3%)
Required6 (10.9%)
Privileges Required
Low16 (29.1%)
High0 (0.0%)
None35 (63.6%)
Unknown4 (7.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (55 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
1.8% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Opensc Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Opensc Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Opensc Project's Products

View all 4 CNAs →

Top CWEs