Opensc

Vendor:

First CVE: Aug 1, 2008 · Active for 17 years

55
Total CVEs
More Total CVEs than 98% of tracked products
5.5
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Opensc over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 1, 2008
17 years ago
Most Recent CVE
May 29, 2026
56 days ago

CVE Severity & Scoring

Opensc55 CVEs
All CVEs352,294 CVEs
LowMediumHigh
Attack Vector
Local6 (10.9%)
Network10 (18.2%)
Unknown4 (7.3%)
Physical35 (63.6%)
Adjacent Network0 (0.0%)
Attack Complexity
Low40 (72.7%)
High11 (20.0%)
Unknown4 (7.3%)
User Interaction
None45 (81.8%)
Unknown4 (7.3%)
Required6 (10.9%)
Privileges Required
Low16 (29.1%)
High0 (0.0%)
None35 (63.6%)
Unknown4 (7.3%)

Top CVEs

Signals from CVEs in this product scope (55 CVEs).

55 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_value() function in src/pkcs15init/profile.c that allows attacke
May 29, 20267.829NONO
OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c that allows physically presen
May 29, 20266.827NONO
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzz_pkcs15_reader harness causes OpenSC to perform an out-of-boun
Mar 30, 20266.825NONO
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token c
Mar 30, 20266.825NONO
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token c
Mar 30, 20266.824NONO
OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sc_compacttlv_find_tag searches a compact-TLV buffer for a given tag. In compact-TLV, a single by
Mar 30, 20266.824NONO
OpenSC before 0.20.0 has a double free in coolkey_free_private_data because coolkey_add_object in libopensc/card-coolkey.c lacks a uniqueness check.
Apr 29, 20206.823NONO
An issue was discovered in the pam_p11 component 0.2.0 and 0.3.0 for OpenSC. If a smart card creates a signature with a length longer than 256 bytes, this triggers a buffer overflo
Sep 6, 20197.523NONO
Several buffer overflows when handling responses from a Gemsafe V1 Smartcard in gemsafe_get_cert_len in libopensc/pkcs15-gemsafeV1.c in OpenSC before 0.19.0-rc1 could be used by at
Sep 3, 20186.823NONO
Several buffer overflows when handling responses from a TCOS Card in tcos_select_file in libopensc/card-tcos.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply
Sep 3, 20186.823NONO

Exploit Exposure

Signals from CVEs in this product scope (55 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
1.8% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (55 CVEs).

Media Mentions

Signals from CVEs in this product scope (55 CVEs).

Top CNAs Publishing CVEs For Opensc

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
0.9.834.70.8%01
0.9.734.70.8%01
0.9.645.20.7%01
0.9.535.30.8%01
0.9.435.30.8%01
0.9.335.30.8%01
0.9.235.30.8%01
0.934.70.8%01
0.8.145.20.7%01
0.8.0.034.70.8%01
0.8.035.30.8%01
0.834.70.8%01
0.7.045.20.7%01
0.6.145.20.7%01
0.6.045.20.7%01
0.5.035.30.8%01
0.4.045.20.7%01
0.3.534.70.8%01
0.3.234.70.8%01
0.3.017.51.5%00