← Back
CWE-193

214 CVEs • Abstraction: Base

Off-by-one Error

A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.

JSON object

Loading...

CVEs (214)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hadrons
1Xfstt
Apr 16, 2026
Aug 27, 2003
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
Off-by-one error in certain versions of xfstt allows remote attackers to read potentially sensitive memory via a malformed client request in the connection handshake, which leaks the memory in the server's response.
7Apple
FreebsdNetbsd+4 more
8Freebsd
Mac Os XMac Os X Server+5 more
Apr 16, 2026
Aug 27, 2003
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathname...Show more
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU, or (8) RNTO.Show less
1Linux Nfs
1Nfs Utils
Apr 16, 2026
Aug 18, 2003
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain RPC requests to...Show more
Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain RPC requests to mountd that do not contain newlines.Show less
1Ethereal
1Ethereal
Apr 16, 2026
Jun 9, 2003
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake,...Show more
Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions.Show less
1Redshift
1Atphttpd
Apr 16, 2026
Dec 31, 2002
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Off-by-one buffer overflow in the sock_gets function in sockhelp.c for ATPhttpd 0.4b and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.
1Microsoft
1Internet Information Services
Apr 16, 2026
Dec 31, 2002
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Off-by-one error in the CodeBrws.asp sample script in Microsoft IIS 5.0 allows remote attackers to view the source code for files with extensions containing with one additional character after .html, .htm, .asp, or .inc,...Show more
Off-by-one error in the CodeBrws.asp sample script in Microsoft IIS 5.0 allows remote attackers to view the source code for files with extensions containing with one additional character after .html, .htm, .asp, or .inc, such as .aspx files.Show less
1Pldaniels
1Altermime
Apr 16, 2026
Dec 31, 2002
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Off-by-one error in alterMIME 0.1.10 and 0.1.11 allows remote attackers to cause a denial of service (crash) via an x-header that causes snprintf overwrite the FFGET_FILE variable with a (null) byte.
1Distrotech
1Cvs
Apr 16, 2026
Aug 12, 2002
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Off-by-one overflow in the CVS PreservePermissions of rcs.c for CVSD before 1.11.2 allows local users to execute arbitrary code.
1Modssl
1Mod Ssl
Apr 16, 2026
Jul 11, 2002
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Off-by-one buffer overflow in the ssl_compat_directive function, as called by the rewrite_command hook for mod_ssl Apache module 2.8.9 and earlier, allows local users to execute arbitrary code as the Apache server user v...Show more
Off-by-one buffer overflow in the ssl_compat_directive function, as called by the rewrite_command hook for mod_ssl Apache module 2.8.9 and earlier, allows local users to execute arbitrary code as the Apache server user via .htaccess files with long entries.Show less
9Conectiva
EngardelinuxImmunix+6 more
11Immunix
LinuxLinux+8 more
Apr 16, 2026
Mar 15, 2002
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
1Acme
1Thttpd
Apr 16, 2026
Dec 31, 2001
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of service and possibly execute arbitrary code.
1Infodrom
1Cfingerd
Apr 16, 2026
Aug 2, 2001
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed ident reply that is passed to the syslog function.
1Linux
1Linux Kernel
Apr 16, 2026
Apr 17, 2001
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Off-by-one vulnerability in CPIA driver of Linux kernel before 2.2.19 allows users to modify kernel memory.
1Ncftp
1Ncftpd Server
Apr 16, 2026
Jan 1, 1999
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Off-by-one error in NcFTPd FTP server before 2.4.1 allows a remote attacker to cause a denial of service (crash) via a long PORT command.