Show filters
93 Total Results
Displaying 51-60 of 93
Sort by:
Attacker Value
Unknown

CVE-2020-26570

Disclosure Date: October 06, 2020 (last updated February 22, 2025)
The Oberthur smart card software driver in OpenSC before 0.21.0-rc1 has a heap-based buffer overflow in sc_oberthur_read_file.
Attacker Value
Unknown

CVE-2020-26571

Disclosure Date: October 06, 2020 (last updated February 22, 2025)
The gemsafe GPK smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in sc_pkcs15emu_gemsafeGPK_init.
Attacker Value
Unknown

CVE-2020-26572

Disclosure Date: October 06, 2020 (last updated February 22, 2025)
The TCOS smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in tcos_decipher.
Attacker Value
Unknown

CVE-2019-20792

Disclosure Date: April 29, 2020 (last updated February 21, 2025)
OpenSC before 0.20.0 has a double free in coolkey_free_private_data because coolkey_add_object in libopensc/card-coolkey.c lacks a uniqueness check.
Attacker Value
Unknown

CVE-2019-19866

Disclosure Date: February 21, 2020 (last updated February 21, 2025)
Atos Unify OpenScape UC Web Client V9 before version V9 R4.31.0 and V10 before version V10 R0.6.0 allows remote attackers to obtain sensitive information. By iterating the value of conferenceId to getMailFunction in the JSON API, one can enumerate all conferences scheduled on the platform, with their numbers and access PINs.
Attacker Value
Unknown

CVE-2019-19865

Disclosure Date: February 21, 2020 (last updated February 21, 2025)
Atos Unify OpenScape UC Application V9 before version V9 R4.31.0 and V10 before version V10 R0.6.0 allows XSS. An attacker could exploit this by convincing an authenticated user to inject arbitrary JavaScript code in the Profile Name field. A browser would execute this stored XSS payload.
Attacker Value
Unknown

CVE-2013-1866

Disclosure Date: January 30, 2020 (last updated February 21, 2025)
OpenSC OpenSC.tokend has an Arbitrary File Creation/Overwrite Vulnerability
Attacker Value
Unknown

CVE-2014-2651

Disclosure Date: January 09, 2020 (last updated February 21, 2025)
Unify OpenStage/OpenScape Desk Phone IP SIP before V3 R3.11.0 has an authentication bypass in the default mode of the Workpoint Interface
Attacker Value
Unknown

CVE-2014-2650

Disclosure Date: January 09, 2020 (last updated February 21, 2025)
Unify OpenStage / OpenScape Desk Phone IP before V3 R3.11.0 SIP has an OS command injection vulnerability in the web based management interface
Attacker Value
Unknown

CVE-2019-19481

Disclosure Date: December 01, 2019 (last updated November 08, 2023)
An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-cac1.c mishandles buffer limits for CAC certificates.