Skip to content
Noroxi

CWE-193 · 207 records

Off-by-one Error

CVEs in this class

207 records

  • Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root

    HighCVSS 7.8KEVWeaponizedEPSS 100%

    sudo project · sudoJan 26, 2021

  • CVE-2003-0466
    62This week

    Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code,

    CriticalCVSS 9.8Proof of conceptEPSS 78%

    redhat · wu ftpdAug 27, 2003

  • GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerability

    HighCVSS 7.8No exploitEPSS 56%

    gimp · gimpMay 2, 2024

  • A Buffer Overflow issue was discovered in Kamailio before 4.4.7, 5.0.x before 5.0.6, and 5.1.x before 5.1.2.

    CriticalCVSS 9.8No exploitEPSS 30%

    kamailio · kamailioMar 20, 2018

  • A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cau

    HighCVSS 7.7Proof of conceptEPSS 53%

    f5 · nginxJun 1, 2021

  • Apache Tomcat: Fix for CVE-2023-24998 is incomplete

    HighCVSS 7.5No exploitEPSS 48%

    apache · tomcatMay 22, 2023

  • Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed id

    CriticalCVSS 9.8Proof of conceptEPSS 18%

    infodrom · cfingerdAug 2, 2001

  • Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a d

    CriticalCVSS 9.8No exploitEPSS 16%

    linux-nfs · nfs-utilsAug 18, 2003

  • Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.

    CriticalCVSS 9.8Proof of conceptEPSS 15%

    immunix · immunixMar 15, 2002

  • Multiple buffer overflows in Gaim 0.75 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) octal

    CriticalCVSS 9.8No exploitEPSS 11%

    gaim project · gaimMar 3, 2004

  • Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute

    CriticalCVSS 9.8No exploitEPSS 10%

    ethereal · etherealJun 9, 2003

  • Off-by-one buffer overflow in the sock_gets function in sockhelp.c for ATPhttpd 0.4b and earlier allows remote attackers to execute arbitrar

    CriticalCVSS 9.8Proof of conceptEPSS 9%

    redshift · atphttpdDec 31, 2002

  • Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers

    CriticalCVSS 9.8No exploitEPSS 7%

    php · phpJan 24, 2017

  • Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow re

    CriticalCVSS 9.3No exploitEPSS 10%

    apache · openofficeJan 28, 2011

  • Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of servic

    CriticalCVSS 9.8No exploitEPSS 5%

    acme · thttpdDec 31, 2001

  • An issue was discovered in libX11 through 1.6.5.

    CriticalCVSS 9.8No exploitEPSS 5%

    x.org · libx11Aug 24, 2018

  • Crow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h.

    CriticalCVSS 9.8Proof of conceptEPSS 4%

    crowcpp · crowAug 4, 2022

  • UltraVNC revision 1206 has multiple off-by-one vulnerabilities in VNC client code connected with improper usage of ClientConnection::ReadStr

    CriticalCVSS 9.8No exploitEPSS 4%

    uvnc · ultravncMar 8, 2019

  • UltraVNC revision 1211 has multiple off-by-one vulnerabilities in VNC server code, which can potentially result in code execution.

    CriticalCVSS 9.8No exploitEPSS 4%

    uvnc · ultravncMar 8, 2019

  • Packet length decoding error in MQTT

    CriticalCVSS 9.8No exploitEPSS 3%

    zephyrproject · zephyrJun 5, 2020

  • In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to an off-by-one heap-bas

    CriticalCVSS 9.8No exploitEPSS 3%

    ossec · ossecJan 29, 2020

  • OFF-BY-ONE ERROR CWE-193

    CriticalCVSS 9.8No exploitEPSS 2%

    secomea · gatemanager 8250 firmwareAug 25, 2020

  • In mjs_json.c in Cesanta MongooseOS mJS 1.26, a maliciously formed JSON string can trigger an off-by-one heap-based buffer overflow in mjs_j

    CriticalCVSS 9.8No exploitEPSS 2%

    cesanta · mongooseos mjsApr 28, 2021

  • An issue was discovered in The Sleuth Kit (TSK) 4.6.6.

    CriticalCVSS 9.8No exploitEPSS 2%

    sleuthkit · the sleuth kitAug 2, 2019

  • OFF-BY-ONE ERROR CWE-193

    CriticalCVSS 9.8No exploitEPSS 2%

    secomea · gatemanager 8250 firmwareAug 25, 2020

All vulnerability classes