CWE-193 · 207 kayıt
Off-by-one Error
Bu sınıftaki CVE’ler
207 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
91Hemen | CVE-2021-3156Silahlaştırılmış | Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root sudo project · sudo · CWE-193 | Yüksek7,8 | KEV | %100,0 | 26 Oca 2021 |
62Bu hafta | CVE-2003-0466Kavram kanıtı | Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code,redhat · wu ftpd · CWE-193 | Kritik9,8 | — | %78,1 | 27 Ağu 2003 |
48Planlayın | CVE-2023-44444İstismar yok | GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerabilitygimp · gimp · CWE-193 | Yüksek7,8 | — | %56,4 | 2 May 2024 |
48Planlayın | CVE-2018-8828İstismar yok | A Buffer Overflow issue was discovered in Kamailio before 4.4.7, 5.0.x before 5.0.6, and 5.1.x before 5.1.2.kamailio · kamailio · CWE-193 | Kritik9,8 | — | %30,4 | 20 Mar 2018 |
46Planlayın | CVE-2021-23017Kavram kanıtı | A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cauf5 · nginx · CWE-193 | Yüksek7,7 | — | %53,5 | 1 Haz 2021 |
44Planlayın | CVE-2023-28709İstismar yok | Apache Tomcat: Fix for CVE-2023-24998 is incompleteapache · tomcat · CWE-193 | Yüksek7,5 | — | %48,0 | 22 May 2023 |
44Planlayın | CVE-2001-0609Kavram kanıtı | Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed idinfodrom · cfingerd · CWE-193 | Kritik9,8 | — | %18,2 | 2 Ağu 2001 |
44Planlayın | CVE-2003-0252İstismar yok | Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a dlinux-nfs · nfs-utils · CWE-193 | Kritik9,8 | — | %15,8 | 18 Ağu 2003 |
43Planlayın | CVE-2002-0083Kavram kanıtı | Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.immunix · immunix · CWE-193 | Kritik9,8 | — | %14,7 | 15 Mar 2002 |
42Planlayın | CVE-2004-0005İstismar yok | Multiple buffer overflows in Gaim 0.75 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) octalgaim project · gaim · CWE-193 | Kritik9,8 | — | %11,2 | 3 Mar 2004 |
42Planlayın | CVE-2003-0356İstismar yok | Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute ethereal · ethereal · CWE-193 | Kritik9,8 | — | %9,6 | 9 Haz 2003 |
42Planlayın | CVE-2002-1816Kavram kanıtı | Off-by-one buffer overflow in the sock_gets function in sockhelp.c for ATPhttpd 0.4b and earlier allows remote attackers to execute arbitrarredshift · atphttpd · CWE-193 | Kritik9,8 | — | %9,0 | 31 Ara 2002 |
41Planlayın | CVE-2016-10160İstismar yok | Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackersphp · php · CWE-193 | Kritik9,8 | — | %7,4 | 24 Oca 2017 |
40Planlayın | CVE-2010-3454İstismar yok | Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow reapache · openoffice · CWE-193 | Kritik9,3 | — | %10,3 | 28 Oca 2011 |
40Planlayın | CVE-2001-1496İstismar yok | Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of servicacme · thttpd · CWE-193 | Kritik9,8 | — | %4,8 | 31 Ara 2001 |
40Planlayın | CVE-2018-14599İstismar yok | An issue was discovered in libX11 through 1.6.5.x.org · libx11 · CWE-193 | Kritik9,8 | — | %4,8 | 24 Ağu 2018 |
40Planlayın | CVE-2022-34970Kavram kanıtı | Crow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h.crowcpp · crow · CWE-193 | Kritik9,8 | — | %4,0 | 4 Ağu 2022 |
40Planlayın | CVE-2019-8268İstismar yok | UltraVNC revision 1206 has multiple off-by-one vulnerabilities in VNC client code connected with improper usage of ClientConnection::ReadStruvnc · ultravnc · CWE-193 | Kritik9,8 | — | %3,9 | 8 Mar 2019 |
40Planlayın | CVE-2019-8272İstismar yok | UltraVNC revision 1211 has multiple off-by-one vulnerabilities in VNC server code, which can potentially result in code execution.uvnc · ultravnc · CWE-193 | Kritik9,8 | — | %3,9 | 8 Mar 2019 |
40Planlayın | CVE-2020-10062İstismar yok | Packet length decoding error in MQTTzephyrproject · zephyr · CWE-193 | Kritik9,8 | — | %2,9 | 5 Haz 2020 |
40Planlayın | CVE-2020-8443İstismar yok | In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to an off-by-one heap-basossec · ossec · CWE-193 | Kritik9,8 | — | %2,7 | 29 Oca 2020 |
40Planlayın | CVE-2020-14510İstismar yok | OFF-BY-ONE ERROR CWE-193secomea · gatemanager 8250 firmware · CWE-193 | Kritik9,8 | — | %2,5 | 25 Ağu 2020 |
40Planlayın | CVE-2021-31875İstismar yok | In mjs_json.c in Cesanta MongooseOS mJS 1.26, a maliciously formed JSON string can trigger an off-by-one heap-based buffer overflow in mjs_jcesanta · mongooseos mjs · CWE-193 | Kritik9,8 | — | %2,2 | 28 Nis 2021 |
40Planlayın | CVE-2019-14532İstismar yok | An issue was discovered in The Sleuth Kit (TSK) 4.6.6.sleuthkit · the sleuth kit · CWE-193 | Kritik9,8 | — | %2,1 | 2 Ağu 2019 |
40Planlayın | CVE-2020-14508İstismar yok | OFF-BY-ONE ERROR CWE-193secomea · gatemanager 8250 firmware · CWE-193 | Kritik9,8 | — | %2,0 | 25 Ağu 2020 |
- CVE-2021-315691Hemen
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %100sudo project · sudo26 Oca 2021
- CVE-2003-046662Bu hafta
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code,
KritikCVSS 9,8Kavram kanıtıEPSS %78redhat · wu ftpd27 Ağu 2003
- CVE-2023-4444448Planlayın
GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerability
YüksekCVSS 7,8İstismar yokEPSS %56gimp · gimp2 May 2024
- CVE-2018-882848Planlayın
A Buffer Overflow issue was discovered in Kamailio before 4.4.7, 5.0.x before 5.0.6, and 5.1.x before 5.1.2.
KritikCVSS 9,8İstismar yokEPSS %30kamailio · kamailio20 Mar 2018
- CVE-2021-2301746Planlayın
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cau
YüksekCVSS 7,7Kavram kanıtıEPSS %53f5 · nginx1 Haz 2021
- CVE-2023-2870944Planlayın
Apache Tomcat: Fix for CVE-2023-24998 is incomplete
YüksekCVSS 7,5İstismar yokEPSS %48apache · tomcat22 May 2023
- CVE-2001-060944Planlayın
Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed id
KritikCVSS 9,8Kavram kanıtıEPSS %18infodrom · cfingerd2 Ağu 2001
- CVE-2003-025244Planlayın
Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a d
KritikCVSS 9,8İstismar yokEPSS %16linux-nfs · nfs-utils18 Ağu 2003
- CVE-2002-008343Planlayın
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
KritikCVSS 9,8Kavram kanıtıEPSS %15immunix · immunix15 Mar 2002
- CVE-2004-000542Planlayın
Multiple buffer overflows in Gaim 0.75 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) octal
KritikCVSS 9,8İstismar yokEPSS %11gaim project · gaim3 Mar 2004
- CVE-2003-035642Planlayın
Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute
KritikCVSS 9,8İstismar yokEPSS %10ethereal · ethereal9 Haz 2003
- CVE-2002-181642Planlayın
Off-by-one buffer overflow in the sock_gets function in sockhelp.c for ATPhttpd 0.4b and earlier allows remote attackers to execute arbitrar
KritikCVSS 9,8Kavram kanıtıEPSS %9redshift · atphttpd31 Ara 2002
- CVE-2016-1016041Planlayın
Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers
KritikCVSS 9,8İstismar yokEPSS %7php · php24 Oca 2017
- CVE-2010-345440Planlayın
Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow re
KritikCVSS 9,3İstismar yokEPSS %10apache · openoffice28 Oca 2011
- CVE-2001-149640Planlayın
Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of servic
KritikCVSS 9,8İstismar yokEPSS %5acme · thttpd31 Ara 2001
- CVE-2018-1459940Planlayın
An issue was discovered in libX11 through 1.6.5.
KritikCVSS 9,8İstismar yokEPSS %5x.org · libx1124 Ağu 2018
- CVE-2022-3497040Planlayın
Crow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h.
KritikCVSS 9,8Kavram kanıtıEPSS %4crowcpp · crow4 Ağu 2022
- CVE-2019-826840Planlayın
UltraVNC revision 1206 has multiple off-by-one vulnerabilities in VNC client code connected with improper usage of ClientConnection::ReadStr
KritikCVSS 9,8İstismar yokEPSS %4uvnc · ultravnc8 Mar 2019
- CVE-2019-827240Planlayın
UltraVNC revision 1211 has multiple off-by-one vulnerabilities in VNC server code, which can potentially result in code execution.
KritikCVSS 9,8İstismar yokEPSS %4uvnc · ultravnc8 Mar 2019
- CVE-2020-1006240Planlayın
Packet length decoding error in MQTT
KritikCVSS 9,8İstismar yokEPSS %3zephyrproject · zephyr5 Haz 2020
- CVE-2020-844340Planlayın
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to an off-by-one heap-bas
KritikCVSS 9,8İstismar yokEPSS %3ossec · ossec29 Oca 2020
- CVE-2020-1451040Planlayın
OFF-BY-ONE ERROR CWE-193
KritikCVSS 9,8İstismar yokEPSS %2secomea · gatemanager 8250 firmware25 Ağu 2020
- CVE-2021-3187540Planlayın
In mjs_json.c in Cesanta MongooseOS mJS 1.26, a maliciously formed JSON string can trigger an off-by-one heap-based buffer overflow in mjs_j
KritikCVSS 9,8İstismar yokEPSS %2cesanta · mongooseos mjs28 Nis 2021
- CVE-2019-1453240Planlayın
An issue was discovered in The Sleuth Kit (TSK) 4.6.6.
KritikCVSS 9,8İstismar yokEPSS %2sleuthkit · the sleuth kit2 Ağu 2019
- CVE-2020-1450840Planlayın
OFF-BY-ONE ERROR CWE-193
KritikCVSS 9,8İstismar yokEPSS %2secomea · gatemanager 8250 firmware25 Ağu 2020