Opensc
Vendor:
First CVE: Aug 1, 2008 · Active for 17 years
55
Total CVEs
More Total CVEs than 98% of tracked products
5.5
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Opensc over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 1, 2008
17 years ago
Most Recent CVE
May 29, 2026
56 days ago
CVE Severity & Scoring
Opensc55 CVEs
16%
71%
13%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local6 (10.9%)
Network10 (18.2%)
Unknown4 (7.3%)
Physical35 (63.6%)
Adjacent Network0 (0.0%)
Attack Complexity
Low40 (72.7%)
High11 (20.0%)
Unknown4 (7.3%)
User Interaction
None45 (81.8%)
Unknown4 (7.3%)
Required6 (10.9%)
Privileges Required
Low16 (29.1%)
High0 (0.0%)
None35 (63.6%)
Unknown4 (7.3%)
Top CVEs
Signals from CVEs in this product scope (55 CVEs).
55 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-40528HIGH OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_value() function in src/pkcs15init/profile.c that allows attacke | May 29, 2026 | 7.8 | 29 | NO | NO |
CVE-2026-40510MEDIUM OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c that allows physically presen | May 29, 2026 | 6.8 | 27 | NO | NO |
CVE-2025-66037MEDIUM OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzz_pkcs15_reader harness causes OpenSC to perform an out-of-boun | Mar 30, 2026 | 6.8 | 25 | NO | NO |
CVE-2025-49010MEDIUM OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token c | Mar 30, 2026 | 6.8 | 25 | NO | NO |
CVE-2025-66215MEDIUM OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token c | Mar 30, 2026 | 6.8 | 24 | NO | NO |
CVE-2025-66038MEDIUM OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sc_compacttlv_find_tag searches a compact-TLV buffer for a given tag. In compact-TLV, a single by | Mar 30, 2026 | 6.8 | 24 | NO | NO |
CVE-2019-20792MEDIUM OpenSC before 0.20.0 has a double free in coolkey_free_private_data because coolkey_add_object in libopensc/card-coolkey.c lacks a uniqueness check. | Apr 29, 2020 | 6.8 | 23 | NO | NO |
CVE-2019-16058HIGH An issue was discovered in the pam_p11 component 0.2.0 and 0.3.0 for OpenSC. If a smart card creates a signature with a length longer than 256 bytes, this triggers a buffer overflo | Sep 6, 2019 | 7.5 | 23 | NO | NO |
CVE-2018-16393MEDIUM Several buffer overflows when handling responses from a Gemsafe V1 Smartcard in gemsafe_get_cert_len in libopensc/pkcs15-gemsafeV1.c in OpenSC before 0.19.0-rc1 could be used by at | Sep 3, 2018 | 6.8 | 23 | NO | NO |
CVE-2018-16392MEDIUM Several buffer overflows when handling responses from a TCOS Card in tcos_select_file in libopensc/card-tcos.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply | Sep 3, 2018 | 6.8 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (55 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
1.8% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (55 CVEs).
Media Mentions
Signals from CVEs in this product scope (55 CVEs).
Top CNAs Publishing CVEs For Opensc
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 0.9.8 | 3 | 4.7 | 0.8% | 0 | 1 |
| 0.9.7 | 3 | 4.7 | 0.8% | 0 | 1 |
| 0.9.6 | 4 | 5.2 | 0.7% | 0 | 1 |
| 0.9.5 | 3 | 5.3 | 0.8% | 0 | 1 |
| 0.9.4 | 3 | 5.3 | 0.8% | 0 | 1 |
| 0.9.3 | 3 | 5.3 | 0.8% | 0 | 1 |
| 0.9.2 | 3 | 5.3 | 0.8% | 0 | 1 |
| 0.9 | 3 | 4.7 | 0.8% | 0 | 1 |
| 0.8.1 | 4 | 5.2 | 0.7% | 0 | 1 |
| 0.8.0.0 | 3 | 4.7 | 0.8% | 0 | 1 |
| 0.8.0 | 3 | 5.3 | 0.8% | 0 | 1 |
| 0.8 | 3 | 4.7 | 0.8% | 0 | 1 |
| 0.7.0 | 4 | 5.2 | 0.7% | 0 | 1 |
| 0.6.1 | 4 | 5.2 | 0.7% | 0 | 1 |
| 0.6.0 | 4 | 5.2 | 0.7% | 0 | 1 |
| 0.5.0 | 3 | 5.3 | 0.8% | 0 | 1 |
| 0.4.0 | 4 | 5.2 | 0.7% | 0 | 1 |
| 0.3.5 | 3 | 4.7 | 0.8% | 0 | 1 |
| 0.3.2 | 3 | 4.7 | 0.8% | 0 | 1 |
| 0.3.0 | 1 | 7.5 | 1.5% | 0 | 0 |