Vulnerabilities > Off-by-one Error

DATE CVE VULNERABILITY TITLE RISK
2022-02-23 CVE-2021-4070 Off-by-one Error vulnerability in V2Fly V2Ray-Core
Off-by-one Error in GitHub repository v2fly/v2ray-core prior to 4.44.0.
network
low complexity
v2fly CWE-193
critical
9.1
2022-02-18 CVE-2021-3930 Off-by-one Error vulnerability in multiple products
An off-by-one error was found in the SCSI device emulation in QEMU.
local
low complexity
qemu redhat debian CWE-193
6.5
2022-02-14 CVE-2022-24988 Off-by-one Error vulnerability in Galois 2P8 Project Galois 2P8 0.1.0/0.1.1
In galois_2p8 before 0.1.2, PrimitivePolynomialField::new has an off-by-one buffer overflow for a vector.
network
low complexity
galois-2p8-project CWE-193
critical
9.8
2021-05-14 CVE-2021-29529 Off-by-one Error vulnerability in Google Tensorflow
TensorFlow is an end-to-end open source platform for machine learning.
local
low complexity
google CWE-193
7.8
2021-04-29 CVE-2021-31875 Off-by-one Error vulnerability in Cesanta Mongooseos MJS 1.26
In mjs_json.c in Cesanta MongooseOS mJS 1.26, a maliciously formed JSON string can trigger an off-by-one heap-based buffer overflow in mjs_json_parse, which can potentially lead to redirection of control flow.
network
low complexity
cesanta CWE-193
critical
9.8
2021-03-20 CVE-2020-27171 Off-by-one Error vulnerability in multiple products
An issue was discovered in the Linux kernel before 5.11.8.
local
low complexity
linux fedoraproject debian canonical CWE-193
6.0
2021-01-26 CVE-2021-3156 Off-by-one Error vulnerability in multiple products
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
7.8
2020-11-24 CVE-2020-29040 Off-by-one Error vulnerability in XEN
An issue was discovered in Xen through 4.14.x allowing x86 HVM guest OS users to cause a denial of service (stack corruption), cause a data leak, or possibly gain privileges because of an off-by-one error.
local
low complexity
xen CWE-193
8.8
2020-08-25 CVE-2020-14508 Off-by-one Error vulnerability in Secomea Gatemanager 8250 Firmware 9.2C
GateManager versions prior to 9.2c, The affected product is vulnerable to an off-by-one error, which may allow an attacker to remotely execute arbitrary code or cause a denial-of-service condition.
network
low complexity
secomea CWE-193
critical
9.8
2020-06-24 CVE-2020-3969 Off-by-one Error vulnerability in VMWare products
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an off-by-one heap-overflow vulnerability in the SVGA device.
local
high complexity
vmware CWE-193
7.8