CWE-193 · 207 records
Off-by-one Error
CVEs in this class
207 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
91Now | CVE-2021-3156Weaponized | Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root sudo project · sudo · CWE-193 | High7.8 | KEV | 100.0% | Jan 26, 2021 |
62This week | CVE-2003-0466Proof of concept | Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code,redhat · wu ftpd · CWE-193 | Critical9.8 | — | 78.1% | Aug 27, 2003 |
48Plan | CVE-2023-44444No exploit | GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerabilitygimp · gimp · CWE-193 | High7.8 | — | 56.4% | May 2, 2024 |
48Plan | CVE-2018-8828No exploit | A Buffer Overflow issue was discovered in Kamailio before 4.4.7, 5.0.x before 5.0.6, and 5.1.x before 5.1.2.kamailio · kamailio · CWE-193 | Critical9.8 | — | 30.4% | Mar 20, 2018 |
46Plan | CVE-2021-23017Proof of concept | A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cauf5 · nginx · CWE-193 | High7.7 | — | 53.5% | Jun 1, 2021 |
44Plan | CVE-2023-28709No exploit | Apache Tomcat: Fix for CVE-2023-24998 is incompleteapache · tomcat · CWE-193 | High7.5 | — | 48.0% | May 22, 2023 |
44Plan | CVE-2001-0609Proof of concept | Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed idinfodrom · cfingerd · CWE-193 | Critical9.8 | — | 18.2% | Aug 2, 2001 |
44Plan | CVE-2003-0252No exploit | Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a dlinux-nfs · nfs-utils · CWE-193 | Critical9.8 | — | 15.8% | Aug 18, 2003 |
43Plan | CVE-2002-0083Proof of concept | Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.immunix · immunix · CWE-193 | Critical9.8 | — | 14.7% | Mar 15, 2002 |
42Plan | CVE-2004-0005No exploit | Multiple buffer overflows in Gaim 0.75 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) octalgaim project · gaim · CWE-193 | Critical9.8 | — | 11.2% | Mar 3, 2004 |
42Plan | CVE-2003-0356No exploit | Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute ethereal · ethereal · CWE-193 | Critical9.8 | — | 9.6% | Jun 9, 2003 |
42Plan | CVE-2002-1816Proof of concept | Off-by-one buffer overflow in the sock_gets function in sockhelp.c for ATPhttpd 0.4b and earlier allows remote attackers to execute arbitrarredshift · atphttpd · CWE-193 | Critical9.8 | — | 9.0% | Dec 31, 2002 |
41Plan | CVE-2016-10160No exploit | Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackersphp · php · CWE-193 | Critical9.8 | — | 7.4% | Jan 24, 2017 |
40Plan | CVE-2010-3454No exploit | Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow reapache · openoffice · CWE-193 | Critical9.3 | — | 10.3% | Jan 28, 2011 |
40Plan | CVE-2001-1496No exploit | Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of servicacme · thttpd · CWE-193 | Critical9.8 | — | 4.8% | Dec 31, 2001 |
40Plan | CVE-2018-14599No exploit | An issue was discovered in libX11 through 1.6.5.x.org · libx11 · CWE-193 | Critical9.8 | — | 4.8% | Aug 24, 2018 |
40Plan | CVE-2022-34970Proof of concept | Crow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h.crowcpp · crow · CWE-193 | Critical9.8 | — | 4.0% | Aug 4, 2022 |
40Plan | CVE-2019-8268No exploit | UltraVNC revision 1206 has multiple off-by-one vulnerabilities in VNC client code connected with improper usage of ClientConnection::ReadStruvnc · ultravnc · CWE-193 | Critical9.8 | — | 3.9% | Mar 8, 2019 |
40Plan | CVE-2019-8272No exploit | UltraVNC revision 1211 has multiple off-by-one vulnerabilities in VNC server code, which can potentially result in code execution.uvnc · ultravnc · CWE-193 | Critical9.8 | — | 3.9% | Mar 8, 2019 |
40Plan | CVE-2020-10062No exploit | Packet length decoding error in MQTTzephyrproject · zephyr · CWE-193 | Critical9.8 | — | 2.9% | Jun 5, 2020 |
40Plan | CVE-2020-8443No exploit | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to an off-by-one heap-basossec · ossec · CWE-193 | Critical9.8 | — | 2.7% | Jan 29, 2020 |
40Plan | CVE-2020-14510No exploit | OFF-BY-ONE ERROR CWE-193secomea · gatemanager 8250 firmware · CWE-193 | Critical9.8 | — | 2.5% | Aug 25, 2020 |
40Plan | CVE-2021-31875No exploit | In mjs_json.c in Cesanta MongooseOS mJS 1.26, a maliciously formed JSON string can trigger an off-by-one heap-based buffer overflow in mjs_jcesanta · mongooseos mjs · CWE-193 | Critical9.8 | — | 2.2% | Apr 28, 2021 |
40Plan | CVE-2019-14532No exploit | An issue was discovered in The Sleuth Kit (TSK) 4.6.6.sleuthkit · the sleuth kit · CWE-193 | Critical9.8 | — | 2.1% | Aug 2, 2019 |
40Plan | CVE-2020-14508No exploit | OFF-BY-ONE ERROR CWE-193secomea · gatemanager 8250 firmware · CWE-193 | Critical9.8 | — | 2.0% | Aug 25, 2020 |
- CVE-2021-315691Now
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root
HighCVSS 7.8KEVWeaponizedEPSS 100%sudo project · sudoJan 26, 2021
- CVE-2003-046662This week
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code,
CriticalCVSS 9.8Proof of conceptEPSS 78%redhat · wu ftpdAug 27, 2003
- CVE-2023-4444448Plan
GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerability
HighCVSS 7.8No exploitEPSS 56%gimp · gimpMay 2, 2024
- CVE-2018-882848Plan
A Buffer Overflow issue was discovered in Kamailio before 4.4.7, 5.0.x before 5.0.6, and 5.1.x before 5.1.2.
CriticalCVSS 9.8No exploitEPSS 30%kamailio · kamailioMar 20, 2018
- CVE-2021-2301746Plan
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cau
HighCVSS 7.7Proof of conceptEPSS 53%f5 · nginxJun 1, 2021
- CVE-2023-2870944Plan
Apache Tomcat: Fix for CVE-2023-24998 is incomplete
HighCVSS 7.5No exploitEPSS 48%apache · tomcatMay 22, 2023
- CVE-2001-060944Plan
Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed id
CriticalCVSS 9.8Proof of conceptEPSS 18%infodrom · cfingerdAug 2, 2001
- CVE-2003-025244Plan
Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a d
CriticalCVSS 9.8No exploitEPSS 16%linux-nfs · nfs-utilsAug 18, 2003
- CVE-2002-008343Plan
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
CriticalCVSS 9.8Proof of conceptEPSS 15%immunix · immunixMar 15, 2002
- CVE-2004-000542Plan
Multiple buffer overflows in Gaim 0.75 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) octal
CriticalCVSS 9.8No exploitEPSS 11%gaim project · gaimMar 3, 2004
- CVE-2003-035642Plan
Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute
CriticalCVSS 9.8No exploitEPSS 10%ethereal · etherealJun 9, 2003
- CVE-2002-181642Plan
Off-by-one buffer overflow in the sock_gets function in sockhelp.c for ATPhttpd 0.4b and earlier allows remote attackers to execute arbitrar
CriticalCVSS 9.8Proof of conceptEPSS 9%redshift · atphttpdDec 31, 2002
- CVE-2016-1016041Plan
Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers
CriticalCVSS 9.8No exploitEPSS 7%php · phpJan 24, 2017
- CVE-2010-345440Plan
Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow re
CriticalCVSS 9.3No exploitEPSS 10%apache · openofficeJan 28, 2011
- CVE-2001-149640Plan
Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of servic
CriticalCVSS 9.8No exploitEPSS 5%acme · thttpdDec 31, 2001
- CVE-2018-1459940Plan
An issue was discovered in libX11 through 1.6.5.
CriticalCVSS 9.8No exploitEPSS 5%x.org · libx11Aug 24, 2018
- CVE-2022-3497040Plan
Crow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h.
CriticalCVSS 9.8Proof of conceptEPSS 4%crowcpp · crowAug 4, 2022
- CVE-2019-826840Plan
UltraVNC revision 1206 has multiple off-by-one vulnerabilities in VNC client code connected with improper usage of ClientConnection::ReadStr
CriticalCVSS 9.8No exploitEPSS 4%uvnc · ultravncMar 8, 2019
- CVE-2019-827240Plan
UltraVNC revision 1211 has multiple off-by-one vulnerabilities in VNC server code, which can potentially result in code execution.
CriticalCVSS 9.8No exploitEPSS 4%uvnc · ultravncMar 8, 2019
- CVE-2020-1006240Plan
Packet length decoding error in MQTT
CriticalCVSS 9.8No exploitEPSS 3%zephyrproject · zephyrJun 5, 2020
- CVE-2020-844340Plan
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to an off-by-one heap-bas
CriticalCVSS 9.8No exploitEPSS 3%ossec · ossecJan 29, 2020
- CVE-2020-1451040Plan
OFF-BY-ONE ERROR CWE-193
CriticalCVSS 9.8No exploitEPSS 2%secomea · gatemanager 8250 firmwareAug 25, 2020
- CVE-2021-3187540Plan
In mjs_json.c in Cesanta MongooseOS mJS 1.26, a maliciously formed JSON string can trigger an off-by-one heap-based buffer overflow in mjs_j
CriticalCVSS 9.8No exploitEPSS 2%cesanta · mongooseos mjsApr 28, 2021
- CVE-2019-1453240Plan
An issue was discovered in The Sleuth Kit (TSK) 4.6.6.
CriticalCVSS 9.8No exploitEPSS 2%sleuthkit · the sleuth kitAug 2, 2019
- CVE-2020-1450840Plan
OFF-BY-ONE ERROR CWE-193
CriticalCVSS 9.8No exploitEPSS 2%secomea · gatemanager 8250 firmwareAug 25, 2020