İçeriğe atla
Noroxi

CWE-193 · 207 kayıt

Off-by-one Error

Bu sınıftaki CVE’ler

207 kayıt

  • Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %100

    sudo project · sudo26 Oca 2021

  • CVE-2003-0466
    62Bu hafta

    Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code,

    KritikCVSS 9,8Kavram kanıtıEPSS %78

    redhat · wu ftpd27 Ağu 2003

  • CVE-2023-44444
    48Planlayın

    GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerability

    YüksekCVSS 7,8İstismar yokEPSS %56

    gimp · gimp2 May 2024

  • CVE-2018-8828
    48Planlayın

    A Buffer Overflow issue was discovered in Kamailio before 4.4.7, 5.0.x before 5.0.6, and 5.1.x before 5.1.2.

    KritikCVSS 9,8İstismar yokEPSS %30

    kamailio · kamailio20 Mar 2018

  • CVE-2021-23017
    46Planlayın

    A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cau

    YüksekCVSS 7,7Kavram kanıtıEPSS %53

    f5 · nginx1 Haz 2021

  • CVE-2023-28709
    44Planlayın

    Apache Tomcat: Fix for CVE-2023-24998 is incomplete

    YüksekCVSS 7,5İstismar yokEPSS %48

    apache · tomcat22 May 2023

  • CVE-2001-0609
    44Planlayın

    Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed id

    KritikCVSS 9,8Kavram kanıtıEPSS %18

    infodrom · cfingerd2 Ağu 2001

  • CVE-2003-0252
    44Planlayın

    Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a d

    KritikCVSS 9,8İstismar yokEPSS %16

    linux-nfs · nfs-utils18 Ağu 2003

  • CVE-2002-0083
    43Planlayın

    Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.

    KritikCVSS 9,8Kavram kanıtıEPSS %15

    immunix · immunix15 Mar 2002

  • CVE-2004-0005
    42Planlayın

    Multiple buffer overflows in Gaim 0.75 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) octal

    KritikCVSS 9,8İstismar yokEPSS %11

    gaim project · gaim3 Mar 2004

  • CVE-2003-0356
    42Planlayın

    Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute

    KritikCVSS 9,8İstismar yokEPSS %10

    ethereal · ethereal9 Haz 2003

  • CVE-2002-1816
    42Planlayın

    Off-by-one buffer overflow in the sock_gets function in sockhelp.c for ATPhttpd 0.4b and earlier allows remote attackers to execute arbitrar

    KritikCVSS 9,8Kavram kanıtıEPSS %9

    redshift · atphttpd31 Ara 2002

  • CVE-2016-10160
    41Planlayın

    Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers

    KritikCVSS 9,8İstismar yokEPSS %7

    php · php24 Oca 2017

  • CVE-2010-3454
    40Planlayın

    Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow re

    KritikCVSS 9,3İstismar yokEPSS %10

    apache · openoffice28 Oca 2011

  • CVE-2001-1496
    40Planlayın

    Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of servic

    KritikCVSS 9,8İstismar yokEPSS %5

    acme · thttpd31 Ara 2001

  • CVE-2018-14599
    40Planlayın

    An issue was discovered in libX11 through 1.6.5.

    KritikCVSS 9,8İstismar yokEPSS %5

    x.org · libx1124 Ağu 2018

  • CVE-2022-34970
    40Planlayın

    Crow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h.

    KritikCVSS 9,8Kavram kanıtıEPSS %4

    crowcpp · crow4 Ağu 2022

  • CVE-2019-8268
    40Planlayın

    UltraVNC revision 1206 has multiple off-by-one vulnerabilities in VNC client code connected with improper usage of ClientConnection::ReadStr

    KritikCVSS 9,8İstismar yokEPSS %4

    uvnc · ultravnc8 Mar 2019

  • CVE-2019-8272
    40Planlayın

    UltraVNC revision 1211 has multiple off-by-one vulnerabilities in VNC server code, which can potentially result in code execution.

    KritikCVSS 9,8İstismar yokEPSS %4

    uvnc · ultravnc8 Mar 2019

  • CVE-2020-10062
    40Planlayın

    Packet length decoding error in MQTT

    KritikCVSS 9,8İstismar yokEPSS %3

    zephyrproject · zephyr5 Haz 2020

  • CVE-2020-8443
    40Planlayın

    In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to an off-by-one heap-bas

    KritikCVSS 9,8İstismar yokEPSS %3

    ossec · ossec29 Oca 2020

  • CVE-2020-14510
    40Planlayın

    OFF-BY-ONE ERROR CWE-193

    KritikCVSS 9,8İstismar yokEPSS %2

    secomea · gatemanager 8250 firmware25 Ağu 2020

  • CVE-2021-31875
    40Planlayın

    In mjs_json.c in Cesanta MongooseOS mJS 1.26, a maliciously formed JSON string can trigger an off-by-one heap-based buffer overflow in mjs_j

    KritikCVSS 9,8İstismar yokEPSS %2

    cesanta · mongooseos mjs28 Nis 2021

  • CVE-2019-14532
    40Planlayın

    An issue was discovered in The Sleuth Kit (TSK) 4.6.6.

    KritikCVSS 9,8İstismar yokEPSS %2

    sleuthkit · the sleuth kit2 Ağu 2019

  • CVE-2020-14508
    40Planlayın

    OFF-BY-ONE ERROR CWE-193

    KritikCVSS 9,8İstismar yokEPSS %2

    secomea · gatemanager 8250 firmware25 Ağu 2020

Tüm zafiyet sınıfları