CVE-2026-103531Medium· 5.5▾ SunlitA flaw has been found in OpenSC up to 0.27.1. The impacted element is the function setcos_construct_fci_44 of the file src/libopensc/card-setcos.c. Executing a manipulation of the argument type_attr can lead to stack-based buffer overflo…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A flaw has been found in OpenSC up to 0.27.1. The impacted element is the function setcos_construct_fci_44 of the file src/libopensc/card-setcos.c. Executing a manipulation of the argument type_attr can lead to stack-based buffer overflow. The attack can be launched remotely. This patch is called ad730304052937c32b4eb489a06835ac6123632c. It is best practice to apply a patch to resolve this issue.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-103226Medium· 6.3A vulnerability was identified in Artifex Ghostscript up to 10.09.0
CVE-2026-101354Critical· 9.6A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4
CVE-2026-101081Critical· 9.1A security flaw has been discovered in D-Link DI-8400 16.07
CVE-2026-101074Critical· 9.8A weakness has been identified in Netcore NR289-GE 1.4.5102
CVE-2026-101039Critical· 10.0A vulnerability was identified in FAST FAC1900R 20190827_2.0.2
CVE-2026-101038Critical· 9.9A vulnerability was determined in FAST FAC1200R 5.0_20201119_1.0.2