CWE-193— Off-by-one Error
169 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-193page 2 of 4
- CVE-2020-27736MEDIUMCVSS 6.5EG 6.52021-04-22
A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (A…
- CVE-2020-27793HIGHCVSS 7.5EG 7.52022-08-19
An off-by-one overflow flaw was found in radare2 due to mismatched array length in core_java.c. This could allow an attacker to cause a crash, and perform a denail of service attack.
- CVE-2020-29040HIGHCVSS 8.8EG 8.82020-11-24
An issue was discovered in Xen through 4.14.x allowing x86 HVM guest OS users to cause a denial of service (stack corruption), cause a data leak, or possibly gain privileges because of an off-by-one error. NOTE: this issue is caused by an …
- CVE-2020-35893HIGHCVSS 7.5EG 7.52020-12-31
An issue was discovered in the simple-slab crate before 0.3.3 for Rust. remove() has an off-by-one error, causing memory leakage and a drop of uninitialized memory.
- CVE-2020-3840HIGHCVSS 7.8EG 7.82020-02-27
An off by one issue existed in the handling of racoon configuration files. This issue was addressed through improved bounds checking. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1. Loading a malic…
- CVE-2020-3969HIGHCVSS 7.8EG 7.82020-06-24
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an off-by-one heap-overflow vulnerability in …
- CVE-2020-6835CRITICALCVSS 9.8EG 9.82020-01-10
An issue was discovered in Bftpd before 5.4. There is a heap-based off-by-one error during file-transfer error checking.
- CVE-2020-7044HIGHCVSS 7.5EG 7.52020-01-16
In Wireshark 3.2.x before 3.2.1, the WASSP dissector could crash. This was addressed in epan/dissectors/packet-wassp.c by using >= and <= to resolve off-by-one errors.
- CVE-2020-8443CRITICALCVSS 9.8EG 9.82020-01-30
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to an off-by-one heap-based buffer overflow during the cleaning of crafted syslog msgs (received from authenticated remote a…
- CVE-2021-21938CRITICALCVSS 9.8EG 8.82022-04-14
A heap-based buffer overflow vulnerability exists in the Palette box parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerabil…
- CVE-2021-23017HIGHCVSS 7.7EG 9.42021-06-01
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.
- CVE-2021-29529LOWCVSS 2.5EG 2.52021-05-14
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a heap buffer overflow in `tf.raw_ops.QuantizedResizeBilinear` by manipulating input values so that float rounding results in off-by-one error i…
- CVE-2021-3156HIGHCVSS 7.8EG 9.0⚠ KEV2021-01-26
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
- CVE-2021-31875CRITICALCVSS 9.8EG 9.82021-04-29
In mjs_json.c in Cesanta MongooseOS mJS 1.26, a maliciously formed JSON string can trigger an off-by-one heap-based buffer overflow in mjs_json_parse, which can potentially lead to redirection of control flow. NOTE: the original reporter d…
- CVE-2021-3930MEDIUMCVSS 6.5EG 6.52022-02-18
An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page' argument was set to MODE_PAGE_ALLS (0x3f). A malicious guest could use this flaw to…
- CVE-2021-3999HIGHCVSS 7.8EG 7.82022-08-24
A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exactly 1. A local attacker who can control the input buffer and size passed to getcwd() in a s…
- CVE-2021-4070CRITICALCVSS 9.1EG 9.12022-02-23
Off-by-one Error in GitHub repository v2fly/v2ray-core prior to 4.44.0.
- CVE-2021-44007MEDIUMCVSS 5.5EG 5.52021-12-14
A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.0.5). The Tiff_Loader.dll contains an off-by-one error in the heap while parsing specially crafted TIFF files. This cou…
- CVE-2021-46848CRITICALCVSS 9.1EG 9.12022-10-24
GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.
- CVE-2021-47046HIGHCVSS 7.8EG 7.82024-02-28
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix off by one in hdmi_14_process_transaction() The hdcp_i2c_offsets[] array did not have an entry for HDCP_MESSAGE_ID_WRITE_CONTENT_STREAM_TYPE so it l…
- CVE-2021-47373MEDIUMCVSS 5.5EG 5.52024-05-21
In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Fix potential VPE leak on error In its_vpe_irq_domain_alloc, when its_vpe_init() returns an error, there is an off-by-one in the number of VPEs to be…
- CVE-2022-23400HIGHCVSS 7.1EG 7.12022-05-03
A stack-based buffer overflow vulnerability exists in the IGXMPXMLParser::parseDelimiter functionality of Accusoft ImageGear 19.10. A specially-crafted PSD file can overflow a stack buffer, which could either lead to denial of service or, …
- CVE-2022-24988CRITICALCVSS 9.8EG 9.82022-02-14
In galois_2p8 before 0.1.2, PrimitivePolynomialField::new has an off-by-one buffer overflow for a vector.
- CVE-2022-25051MEDIUMCVSS 5.5EG 5.52022-03-02
An Off-by-one Error occurs in cmr113_decode of rtl_433 21.12 when decoding a crafted file.
- CVE-2022-30155MEDIUMCVSS 5.5EG 5.52022-06-15
Windows Kernel Denial of Service Vulnerability
- CVE-2022-3103HIGHCVSS 7.8EG 7.82022-09-26
off-by-one in io_uring module.
- CVE-2022-33064HIGHCVSS 7.8EG 7.82023-07-18
An off-by-one error in function wav_read_header in src/wav.c in Libsndfile 1.1.0, results in a write out of bound, which allows an attacker to execute arbitrary code, Denial of Service or other unspecified impacts.
- CVE-2022-34684MEDIUMCVSS 5.3EG 5.32022-12-30
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an off-by-one error may lead to data tampering or information disclosure.
- CVE-2022-34970CRITICALCVSS 9.8EG 9.82022-08-04
Crow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h. On successful exploitation this vulnerability allows attackers to remotely execute arbitrary code in the context of the vulnerable service.
- CVE-2022-36354MEDIUMCVSS 5.3EG 5.32022-12-22
A heap out-of-bounds read vulnerability exists in the RLA format parser of OpenImageIO master-branch-9aeece7a and v2.3.19.0. More specifically, in the way run-length encoded byte spans are handled. A malformed RLA file can lead to an out-o…
- CVE-2022-3821MEDIUMCVSS 5.5EG 5.52022-11-08
An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Serv…
- CVE-2022-3872HIGHCVSS 8.6EG 8.62022-11-07
An off-by-one read/write issue was found in the SDHCI device of QEMU. It occurs when reading/writing the Buffer Data Port Register in sdhci_read_dataport and sdhci_write_dataport, respectively, if data_count == block_size. A malicious gues…
- CVE-2022-39274HIGHCVSS 7.5EG 7.52022-10-06
LoRaMac-node is a reference implementation and documentation of a LoRa network node. Versions of LoRaMac-node prior to 4.7.0 are vulnerable to a buffer overflow. Improper size validation of the incoming radio frames can lead to an 65280-by…
- CVE-2022-41916MEDIUMCVSS 5.9EG 5.92022-11-15
Heimdal is an implementation of ASN.1/DER, PKIX, and Kerberos. Versions prior to 7.7.1 are vulnerable to a denial of service vulnerability in Heimdal's PKI certificate validation library, affecting the KDC (via PKINIT) and kinit (via PKINI…
- CVE-2022-47517HIGHCVSS 7.5EG 7.52022-12-18
An issue was discovered in the libsofia-sip fork in drachtio-server before 0.8.19. It allows remote attackers to cause a denial of service (daemon crash) via a crafted UDP message that causes a url_canonize2 heap-based buffer over-read bec…
- CVE-2022-48672HIGHCVSS 7.8EG 7.82024-05-03
In the Linux kernel, the following vulnerability has been resolved: of: fdt: fix off-by-one error in unflatten_dt_nodes() Commit 78c44d910d3e ("drivers/of: Fix depth when unflattening devicetree") forgot to fix up the depth check in the …
- CVE-2022-48732HIGHCVSS 7.8EG 7.82024-06-20
In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix off by one in BIOS boundary checking Bounds checking when parsing init scripts embedded in the BIOS reject access to the last byte. This causes driver i…
- CVE-2022-49077MEDIUMCVSS 5.5EG 5.52025-02-26
In the Linux kernel, the following vulnerability has been resolved: mmmremap.c: avoid pointless invalidate_range_start/end on mremap(old_size=0) If an mremap() syscall with old_size=0 ends up in move_page_tables(), it will call invalidat…
- CVE-2022-49365MEDIUMCVSS 5.5EG 5.52025-02-26
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Off by one in dm_dmub_outbox1_low_irq() The > ARRAY_SIZE() should be >= ARRAY_SIZE() to prevent an out of bounds access.
- CVE-2022-50428MEDIUMCVSS 5.5EG 5.52025-10-01
In the Linux kernel, the following vulnerability has been resolved: ext4: fix off-by-one errors in fast-commit block filling Due to several different off-by-one errors, or perhaps due to a late change in design that wasn't fully reflecte…
- CVE-2023-0818MEDIUMCVSS 5.5EG 5.52023-02-13
Off-by-one Error in GitHub repository gpac/gpac prior to v2.3.0-DEV.
- CVE-2023-27477LOWCVSS 3.1EG 3.12023-03-08
wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's code generation backend, Cranelift, has a bug on x86_64 platforms for the WebAssembly `i8x16.select` instruction which will produce the wrong results when the same operand i…
- CVE-2023-28709HIGHCVSS 7.5EG 7.52023-05-22
The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector settings were used such that the maxParameterCount could be r…
- CVE-2023-28858LOWCVSS 3.7EG 3.72023-03-26
redis-py before 4.5.3 leaves a connection open after canceling an async Redis command at an inopportune time, and can send response data to the client of an unrelated request in an off-by-one manner. NOTE: this CVE Record was initially cre…
- CVE-2023-30546CRITICALCVSS 9.8EG 9.82023-04-26
Contiki-NG is an operating system for Internet of Things devices. An off-by-one error can be triggered in the Antelope database management system in the Contiki-NG operating system in versions 4.8 and prior. The problem exists in the Conti…
- CVE-2023-38429CRITICALCVSS 9.8EG 9.82023-07-18
An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/connection.c in ksmbd has an off-by-one error in memory allocation (because of ksmbd_smb2_check_message) that may lead to out-of-bounds access.
- CVE-2023-41880LOWCVSS 2.2EG 2.22023-09-15
Wasmtime is a standalone runtime for WebAssembly. Wasmtime versions from 10.0.0 to versions 10.02, 11.0.2, and 12.0.1 contain a miscompilation of the WebAssembly `i64x2.shr_s` instruction on x86_64 platforms when the shift amount is a cons…
- CVE-2023-4259HIGHCVSS 7.1EG 7.12023-09-26
Two potential buffer overflow vulnerabilities at the following locations in the Zephyr eS-WiFi driver source code.
- CVE-2023-4260MEDIUMCVSS 6.3EG 6.32023-09-27
Potential off-by-one buffer overflow vulnerability in the Zephyr fuse file system.
- CVE-2023-44444HIGHCVSS 7.8EG 7.82024-05-03
GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in tha…
Map vulnerabilities like CWE-193 to your infrastructure
EchelonGraph correlates every CVE — across CWE-193 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →