Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 18 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-120 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 03 Jun 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opensc Project
Opensc Project opensc |
|
| CPEs | cpe:2.3:a:opensc_project:opensc:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Opensc Project
Opensc Project opensc |
Mon, 01 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opensc
Opensc opensc |
|
| Vendors & Products |
Opensc
Opensc opensc |
Fri, 29 May 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c that allows physically present attackers to trigger memory corruption by presenting a crafted PIV smart card or USB device returning a URL field longer than 118 bytes in the Key History Object ASN.1 response. | |
| Title | OpenSC < 0.27.0-rc1 Stack Buffer Overflow via piv_process_history() in card-piv.c | |
| Weaknesses | CWE-121 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-01T13:37:24.127Z
Reserved: 2026-04-13T20:29:02.809Z
Link: CVE-2026-40510
Updated: 2026-06-01T13:37:09.966Z
Status : Analyzed
Published: 2026-05-29T14:16:26.540
Modified: 2026-06-03T14:30:15.123
Link: CVE-2026-40510
OpenCVE Enrichment
Updated: 2026-06-18T19:00:11Z