CWE-193
214 CVEs • Abstraction: Base
Off-by-one Error
A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.
CVEs (214)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in the libsofia-sip fork in drachtio-server before 0.8.19. It allows remote attackers to cause a denial of service (daemon crash) via a crafted UDP message that causes a url_canonize2 heap-based b...Show more |
2Debian Heimdal Project2Debian Linux HeimdalJun 17, 2026 Nov 15, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Heimdal is an implementation of ASN.1/DER, PKIX, and Kerberos. Versions prior to 7.7.1 are vulnerable to a denial of service vulnerability in Heimdal's PKI certificate validation library, affecting the KDC (via PKINIT) a...Show more |
3Fedoraproject RedhatSystemd Project3Enterprise Linux FedoraSystemdJun 17, 2026 Nov 8, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading...Show more |
An off-by-one read/write issue was found in the SDHCI device of QEMU. It occurs when reading/writing the Buffer Data Port Register in sdhci_read_dataport and sdhci_write_dataport, respectively, if data_count == block_siz...Show more |
3Debian FedoraprojectGnu3Debian Linux FedoraLibtasn1Jun 17, 2026 Oct 24, 2022 N/A· v4 9.1 CRITICAL· v3 N/A· v2 GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der. |
LoRaMac-node is a reference implementation and documentation of a LoRa network node. Versions of LoRaMac-node prior to 4.7.0 are vulnerable to a buffer overflow. Improper size validation of the incoming radio frames can...Show more |
off-by-one in io_uring module. |
3Debian GnuNetapp10Debian Linux E Series Performance AnalyzerGlibc+7 moreJun 17, 2026 Aug 24, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exactly 1. A local attacker who can control the input buffer and size passed...Show more |
An off-by-one overflow flaw was found in radare2 due to mismatched array length in core_java.c. This could allow an attacker to cause a crash, and perform a denail of service attack. |
Crow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h. On successful exploitation this vulnerability allows attackers to remotely execute arbitrary code in the context of the vuln...Show more |
1Microsoft 10Windows 10 Windows 11Windows 7+7 moreJun 17, 2026 Jun 15, 2022 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 Windows Kernel Denial of Service Vulnerability |
A stack-based buffer overflow vulnerability exists in the IGXMPXMLParser::parseDelimiter functionality of Accusoft ImageGear 19.10. A specially-crafted PSD file can overflow a stack buffer, which could either lead to den...Show more |
A heap-based buffer overflow vulnerability exists in the Palette box parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to code execution. An attacker can provide a malicious file to trig...Show more |
An Off-by-one Error occurs in cmr113_decode of rtl_433 21.12 when decoding a crafted file. |
Off-by-one Error in GitHub repository v2fly/v2ray-core prior to 4.44.0. |
3Debian QemuRedhat10Codeready Linux Builder Codeready Linux Builder For Ibm Z SystemsCodeready Linux Builder For Power Little Endian+7 moreJun 17, 2026 Feb 18, 2022 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page' argument was set to MODE_PAGE_ALLS (0x3f). A malicious guest cou...Show more |
1Galois 2p8 Project 1Galois 2p8 Jun 17, 2026 Feb 14, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In galois_2p8 before 0.1.2, PrimitivePolynomialField::new has an off-by-one buffer overflow for a vector. |
1Siemens 2Jt2go Teamcenter VisualizationJun 17, 2026 Dec 14, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.0.5). The Tiff_Loader.dll contains an off-by-one error in the heap while parsing specially crafted T...Show more |
5F5 FedoraprojectNetapp+2 more13Blockchain Platform Communications Control Plane MonitorCommunications Fraud Monitor+10 moreJun 17, 2026 Jun 1, 2021 N/A· v4 7.7 HIGH· v3 6.8 MEDIUM· v2 A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other...Show more |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a heap buffer overflow in `tf.raw_ops.QuantizedResizeBilinear` by manipulating input values so that float rounding results in...Show more |