VYPR

CWE-193

Off-by-one Error

BaseDraft

Description

A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (221)

page 10 of 12
  • CVE-2026-50497MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.01

    Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-7831HigJul 1, 2026
    risk 0.00cvss 7.6epss 0.01

    UltraVNC viewer through 1.8.2.2 contains an off-by-one stack buffer overflow in the RFB ServerInit message handler. In vncviewer/ClientConnection.cpp, when the server-supplied nameLength equals exactly 2024 the code declares a 2024-byte stack buffer _dn[2024] and calls…

  • CVE-2026-44042LowJul 1, 2026
    risk 0.00cvss 3.7epss 0.00

    UltraVNC repeater through 1.8.2.2 contains an off-by-one error in the Base64 decode helper used for HTTP Basic authentication. In repeater/webgui/webutils.c:817, the wi_uudecode() function checks whether the input length exceeds the output buffer with a strict greater-than…

  • CVE-2026-56790HigJun 25, 2026
    risk 0.00cvss 7.3epss 0.00

    CANBoat through 6.22, fixed in commit a5a22b7, contains an off-by-one global buffer overflow in the searchForPgn() function in analyzer/pgn.c that allows remote attackers to crash the application. Attackers can deliver a crafted NMEA-2000 message with an out-of-range PGN value…

  • CVE-2026-21870MedFeb 13, 2026
    risk 0.00cvss 5.5epss 0.00

    BACnet Protocol Stack library provides a BACnet application layer, network layer and media access (MAC) layer communications services. In 1.4.2, 1.5.0.rc2, and earlier, an off-by-one stack-based buffer overflow in the ubasic interpreter causes a crash (SIGABRT) when processing…

  • CVE-2026-21504MedJan 7, 2026
    risk 0.00cvss 6.6epss 0.00

    iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to heap buffer overflow in the ToneMap parser. This issue has been patched in version…

  • CVE-2026-21494MedJan 6, 2026
    risk 0.00cvss 6.1epss 0.00

    iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. A vulnerability present in versions prior to 2.3.1.2 affects users of the iccDEV library who process ICC…

  • CVE-2026-21491MedJan 6, 2026
    risk 0.00cvss 6.1epss 0.00

    iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. A vulnerability present in versions prior to 2.3.1.2 affects users of the iccDEV library who process ICC…

  • CVE-2026-21490MedJan 6, 2026
    risk 0.00cvss 6.1epss 0.00

    iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. A vulnerability present in versions prior to 2.3.1.2 affects users of the iccDEV library who process ICC…

  • CVE-2025-54349MedAug 3, 2025
    risk 0.00cvss 6.5epss 0.00

    In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.

  • CVE-2024-31585MedApr 17, 2024
    risk 0.00cvss 5.3epss 0.00

    FFmpeg version n5.1 to n6.1 was discovered to contain an Off-by-one Error vulnerability in libavfilter/avf_showspectrum.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2024-23849MedJan 23, 2024
    risk 0.00cvss 5.5epss 0.00

    In rds_recv_track_latency in net/rds/af_rds.c in the Linux kernel through 6.7.1, there is an off-by-one error for an RDS_MSG_RX_DGRAM_TRACE_MAX comparison, resulting in out-of-bounds access.

  • CVE-2023-46853CriOct 27, 2023
    risk 0.00cvss 9.8epss 0.01

    In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of \r\n.

  • CVE-2023-38429CriJul 18, 2023
    risk 0.00cvss 9.8epss 0.01

    An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/connection.c in ksmbd has an off-by-one error in memory allocation (because of ksmbd_smb2_check_message) that may lead to out-of-bounds access.

  • CVE-2023-30546CriApr 26, 2023
    risk 0.00cvss 9.8epss 0.01

    Contiki-NG is an operating system for Internet of Things devices. An off-by-one error can be triggered in the Antelope database management system in the Contiki-NG operating system in versions 4.8 and prior. The problem exists in the Contiki File System (CFS) backend for the…

  • CVE-2023-0818MedFeb 13, 2023
    risk 0.00cvss 5.5epss 0.00

    Off-by-one Error in GitHub repository gpac/gpac prior to v2.3.0-DEV.

  • CVE-2022-47517HigDec 18, 2022
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in the libsofia-sip fork in drachtio-server before 0.8.19. It allows remote attackers to cause a denial of service (daemon crash) via a crafted UDP message that causes a url_canonize2 heap-based buffer over-read because of an off-by-one error.

  • CVE-2022-3821MedNov 8, 2022
    risk 0.00cvss 5.5epss 0.00

    An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service.

  • CVE-2021-46848CriOct 24, 2022
    risk 0.00cvss 9.1epss 0.02

    GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.

  • CVE-2022-39274HigOct 6, 2022
    risk 0.00cvss 7.5epss 0.02

    LoRaMac-node is a reference implementation and documentation of a LoRa network node. Versions of LoRaMac-node prior to 4.7.0 are vulnerable to a buffer overflow. Improper size validation of the incoming radio frames can lead to an 65280-byte out-of-bounds write. The function…