Перейти к содержимому
Noroxi

CWE-193 · 207 записей

Off-by-one Error

CVE этого класса

207 записей

  • CVE-2021-3156
    91Срочно

    Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 100 %

    sudo project · sudo26 янв. 2021 г.

  • CVE-2003-0466
    62На этой неделе

    Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code,

    КритическаяCVSS 9,8Proof of conceptEPSS 78 %

    redhat · wu ftpd27 авг. 2003 г.

  • CVE-2023-44444
    48В плане

    GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerability

    ВысокаяCVSS 7,8Эксплойта нетEPSS 56 %

    gimp · gimp2 мая 2024 г.

  • CVE-2018-8828
    48В плане

    A Buffer Overflow issue was discovered in Kamailio before 4.4.7, 5.0.x before 5.0.6, and 5.1.x before 5.1.2.

    КритическаяCVSS 9,8Эксплойта нетEPSS 30 %

    kamailio · kamailio20 мар. 2018 г.

  • CVE-2021-23017
    46В плане

    A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cau

    ВысокаяCVSS 7,7Proof of conceptEPSS 53 %

    f5 · nginx1 июн. 2021 г.

  • CVE-2023-28709
    44В плане

    Apache Tomcat: Fix for CVE-2023-24998 is incomplete

    ВысокаяCVSS 7,5Эксплойта нетEPSS 48 %

    apache · tomcat22 мая 2023 г.

  • CVE-2001-0609
    44В плане

    Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed id

    КритическаяCVSS 9,8Proof of conceptEPSS 18 %

    infodrom · cfingerd2 авг. 2001 г.

  • CVE-2003-0252
    44В плане

    Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a d

    КритическаяCVSS 9,8Эксплойта нетEPSS 16 %

    linux-nfs · nfs-utils18 авг. 2003 г.

  • CVE-2002-0083
    43В плане

    Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.

    КритическаяCVSS 9,8Proof of conceptEPSS 15 %

    immunix · immunix15 мар. 2002 г.

  • CVE-2004-0005
    42В плане

    Multiple buffer overflows in Gaim 0.75 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) octal

    КритическаяCVSS 9,8Эксплойта нетEPSS 11 %

    gaim project · gaim3 мар. 2004 г.

  • CVE-2003-0356
    42В плане

    Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute

    КритическаяCVSS 9,8Эксплойта нетEPSS 10 %

    ethereal · ethereal9 июн. 2003 г.

  • CVE-2002-1816
    42В плане

    Off-by-one buffer overflow in the sock_gets function in sockhelp.c for ATPhttpd 0.4b and earlier allows remote attackers to execute arbitrar

    КритическаяCVSS 9,8Proof of conceptEPSS 9 %

    redshift · atphttpd31 дек. 2002 г.

  • CVE-2016-10160
    41В плане

    Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers

    КритическаяCVSS 9,8Эксплойта нетEPSS 7 %

    php · php24 янв. 2017 г.

  • CVE-2010-3454
    40В плане

    Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow re

    КритическаяCVSS 9,3Эксплойта нетEPSS 10 %

    apache · openoffice28 янв. 2011 г.

  • CVE-2001-1496
    40В плане

    Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of servic

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    acme · thttpd31 дек. 2001 г.

  • CVE-2018-14599
    40В плане

    An issue was discovered in libX11 through 1.6.5.

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    x.org · libx1124 авг. 2018 г.

  • CVE-2022-34970
    40В плане

    Crow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h.

    КритическаяCVSS 9,8Proof of conceptEPSS 4 %

    crowcpp · crow4 авг. 2022 г.

  • CVE-2019-8268
    40В плане

    UltraVNC revision 1206 has multiple off-by-one vulnerabilities in VNC client code connected with improper usage of ClientConnection::ReadStr

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    uvnc · ultravnc8 мар. 2019 г.

  • CVE-2019-8272
    40В плане

    UltraVNC revision 1211 has multiple off-by-one vulnerabilities in VNC server code, which can potentially result in code execution.

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    uvnc · ultravnc8 мар. 2019 г.

  • CVE-2020-10062
    40В плане

    Packet length decoding error in MQTT

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    zephyrproject · zephyr5 июн. 2020 г.

  • CVE-2020-8443
    40В плане

    In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to an off-by-one heap-bas

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    ossec · ossec29 янв. 2020 г.

  • CVE-2020-14510
    40В плане

    OFF-BY-ONE ERROR CWE-193

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    secomea · gatemanager 8250 firmware25 авг. 2020 г.

  • CVE-2021-31875
    40В плане

    In mjs_json.c in Cesanta MongooseOS mJS 1.26, a maliciously formed JSON string can trigger an off-by-one heap-based buffer overflow in mjs_j

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    cesanta · mongooseos mjs28 апр. 2021 г.

  • CVE-2019-14532
    40В плане

    An issue was discovered in The Sleuth Kit (TSK) 4.6.6.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    sleuthkit · the sleuth kit2 авг. 2019 г.

  • CVE-2020-14508
    40В плане

    OFF-BY-ONE ERROR CWE-193

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    secomea · gatemanager 8250 firmware25 авг. 2020 г.

Все классы уязвимостей