Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 18 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-120 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 03 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opensc Project
Opensc Project opensc |
|
| CPEs | cpe:2.3:a:opensc_project:opensc:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Opensc Project
Opensc Project opensc |
Fri, 29 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opensc
Opensc opensc |
|
| Vendors & Products |
Opensc
Opensc opensc |
Fri, 29 May 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_value() function in src/pkcs15init/profile.c that allows attackers to corrupt memory by supplying a crafted profile configuration file. During pkcs15-init invocation, a key value entry beginning with '=' followed by more than sizeof(keybuf) characters is copied into keybuf via memcpy without a length check, causing both stack and heap buffer overruns. | |
| Title | OpenSC < 0.27.0 Buffer Overrun in do_key_value() via profile.c | |
| Weaknesses | CWE-121 CWE-122 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-29T13:58:18.086Z
Reserved: 2026-04-13T20:29:02.810Z
Link: CVE-2026-40528
Updated: 2026-05-29T13:58:12.442Z
Status : Analyzed
Published: 2026-05-29T14:16:26.730
Modified: 2026-06-03T14:28:17.190
Link: CVE-2026-40528
OpenCVE Enrichment
Updated: 2026-06-18T20:30:05Z