VYPR

CWE-193

Off-by-one Error

BaseDraft

Description

A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (238)

page 10 of 12
  • CVE-2026-43964LowMay 4, 2026
    risk 0.17cvss 3.7epss 0.01

    Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.

  • CVE-2026-43860LowMay 4, 2026
    risk 0.17cvss 3.7epss 0.00

    mutt before 2.3.2 sometimes truncates the hash_passwd by one byte for IMAP auth_cram MD5 digest.

  • CVE-2026-5123LowMar 30, 2026
    risk 0.17cvss 3.7epss 0.00

    A weakness has been identified in osrg GoBGP up to 4.3.0. This impacts the function DecodeFromBytes of the file pkg/packet/bgp/bgp.go. Executing a manipulation of the argument data[1] can lead to off-by-one. The attack may be launched remotely. Attacks of this nature are highly…

  • CVE-2025-53014LowJul 14, 2025
    risk 0.17cvss 3.7epss 0.01

    ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-0 and 6.9.13-26 have a heap buffer overflow in the `InterpretImageFilename` function. The issue stems from an off-by-one error that causes out-of-bounds memory…

  • CVE-2023-28858LowMar 26, 2023
    risk 0.17cvss 3.7epss 0.01

    redis-py before 4.5.3 leaves a connection open after canceling an async Redis command at an inopportune time, and can send response data to the client of an unrelated request in an off-by-one manner. NOTE: this CVE Record was initially created in response to reports about…

  • CVE-2026-2703LowFeb 19, 2026
    risk 0.14cvss 3.3epss 0.00

    A weakness has been identified in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::decode_base64 of the file source/detail/cryptography/base64.cpp of the component Encrypted XLSX File Parser. Executing a manipulation can lead to off-by-one. The attack…

  • CVE-2026-45232LowMay 20, 2026
    risk 0.13cvss 3.1epss 0.00

    Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connection() function in socket.c that allows network attackers to corrupt stack memory by sending a malformed HTTP proxy response. Attackers can exploit this by…

  • CVE-2023-27477LowMar 8, 2023
    risk 0.13cvss 3.1epss 0.01

    wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's code generation backend, Cranelift, has a bug on x86_64 platforms for the WebAssembly `i8x16.select` instruction which will produce the wrong results when the same operand is provided to the instruction and some…

  • CVE-2021-29529LowMay 14, 2021
    risk 0.09cvss 2.5epss 0.00

    TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a heap buffer overflow in `tf.raw_ops.QuantizedResizeBilinear` by manipulating input values so that float rounding results in off-by-one error in accessing image elements. This is…

  • CVE-2026-81738LowSep 7, 2026
    risk 0.08cvss —epss 0.00

    OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries

  • CVE-2023-41880LowSep 15, 2023
    risk 0.07cvss 2.2epss 0.01

    Wasmtime is a standalone runtime for WebAssembly. Wasmtime versions from 10.0.0 to versions 10.02, 11.0.2, and 12.0.1 contain a miscompilation of the WebAssembly `i64x2.shr_s` instruction on x86_64 platforms when the shift amount is a constant value that is larger than 32. Only…

  • CVE-2009-1217Apr 1, 2009
    risk 0.04cvss —epss 0.16

    Off-by-one error in the GpFont::SetData function in gdiplus.dll in Microsoft GDI+ on Windows XP allows remote attackers to cause a denial of service (stack corruption and application termination) via a crafted EMF file that triggers an integer overflow, as demonstrated by…

  • CVE-2007-2052Apr 16, 2007
    risk 0.04cvss —epss 0.14

    Off-by-one error in the PyLocale_strxfrm function in Modules/_localemodule.c for Python 2.4 and 2.5 causes an incorrect buffer size to be used for the strxfrm function, which allows context-dependent attackers to read portions of memory via unknown manipulations that trigger a…

  • CVE-2018-8828CriMar 20, 2018
    risk 0.03cvss 9.8epss 0.30

    A Buffer Overflow issue was discovered in Kamailio before 4.4.7, 5.0.x before 5.0.6, and 5.1.x before 5.1.2. A specially crafted REGISTER message with a malformed branch or From tag triggers an off-by-one heap-based buffer overflow in the tmx_check_pretran function in…

  • CVE-2010-3454Jan 28, 2011
    risk 0.01cvss —epss 0.10

    Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted typography information in a…

  • CVE-2005-1268Aug 5, 2005
    risk 0.01cvss —epss 0.08

    Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.

  • CVE-2026-93018Sep 18, 2026
    risk 0.00cvss —epss 0.00

    Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p. The palette is allocated uninitialised, and only the entries a reader adds count as populated. The TGA reader…

  • CVE-2026-50497MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.01

    Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-7831HigJul 1, 2026
    risk 0.00cvss 7.6epss 0.01

    UltraVNC viewer through 1.8.2.2 contains an off-by-one stack buffer overflow in the RFB ServerInit message handler. In vncviewer/ClientConnection.cpp, when the server-supplied nameLength equals exactly 2024 the code declares a 2024-byte stack buffer _dn[2024] and calls…

  • CVE-2026-44042LowJul 1, 2026
    risk 0.00cvss 3.7epss 0.00

    UltraVNC repeater through 1.8.2.2 contains an off-by-one error in the Base64 decode helper used for HTTP Basic authentication. In repeater/webgui/webutils.c:817, the wi_uudecode() function checks whether the input length exceeds the output buffer with a strict greater-than…