Muscle Pcsc-Lite vulnerabilities
6 known vulnerabilities affecting muscle/pcsc-lite.
Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM4LOW1
Vulnerabilities
Page 1 of 1
CVE-2016-10109P3HIGHCVSS 7.5≤ 1.8.192017-02-23
CVE-2016-10109 [HIGH] CWE-416 CVE-2016-10109: Use-after-free vulnerability in pcsc-lite before 1.8.20 allows a remote attackers to cause denial of
Use-after-free vulnerability in pcsc-lite before 1.8.20 allows a remote attackers to cause denial of service (crash) via a command that uses "cardsList" after the handle has been released through the SCardReleaseContext function.
nvdosv
CVE-2010-0407P4MEDIUMCVSS 6.8≤ 1.5.3v1.1.2+18 more2010-06-18
CVE-2010-0407 [MEDIUM] CWE-119 CVE-2010-0407: Multiple buffer overflows in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart
Multiple buffer overflows in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 allow local users to gain privileges via crafted message data, which is improperly demarshalled.
nvdosv
CVE-2009-4902P4MEDIUMCVSS 6.8≤ 1.5.4v1.1.2+18 more2010-06-18
CVE-2009-4902 [MEDIUM] CWE-119 CVE-2009-4902: Buffer overflow in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daem
Buffer overflow in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite 1.5.4 and earlier might allow local users to gain privileges via crafted SCARD_CONTROL message data, which is improperly demarshalled. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-0407.
nvd
CVE-2010-4530P4MEDIUMCVSS 4.4v1.5.32011-01-18
CVE-2010-4530 [MEDIUM] CWE-189 CVE-2010-4530: Signedness error in ccid_serial.c in libccid in the USB Chip/Smart Card Interface Devices (CCID) dri
Signedness error in ccid_serial.c in libccid in the USB Chip/Smart Card Interface Devices (CCID) driver, as used in pcscd in PCSC-Lite 1.5.3 and possibly other products, allows physically proximate attackers to execute arbitrary code via a smart card with a crafted serial number that causes a negative value to be used in a memcpy operation, which trig
nvd
CVE-2010-4531P4MEDIUMCVSS 4.4v1.5.32011-01-18
CVE-2010-4531 [MEDIUM] CWE-119 CVE-2010-4531: Stack-based buffer overflow in the ATRDecodeAtr function in the Answer-to-Reset (ATR) Handler (atrha
Stack-based buffer overflow in the ATRDecodeAtr function in the Answer-to-Reset (ATR) Handler (atrhandler.c) for pcscd in PCSC-Lite 1.5.3, and possibly other 1.5.x and 1.6.x versions, allows physically proximate attackers to cause a denial of service (crash) and possibly execute arbitrary code via a smart card with an ATR message containing a long att
nvdosv
CVE-2009-4901P4LOWCVSS 2.1≤ 1.5.3v1.1.2+18 more2010-06-18
CVE-2009-4901 [LOW] CWE-119 CVE-2009-4901: The MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in M
The MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 might allow local users to cause a denial of service (daemon crash) via crafted SCARD_SET_ATTRIB message data, which is improperly demarshalled and triggers a buffer over-read, a related issue to CVE-2010-0407.
nvd