Vulnerabilities > Off-by-one Error

DATE CVE VULNERABILITY TITLE RISK
2017-09-17 CVE-2017-14502 Off-by-one Error vulnerability in Libarchive 3.3.2
read_header in archive_read_support_format_rar.c in libarchive 3.3.2 suffers from an off-by-one error for UTF-16 names in RAR archives, leading to an out-of-bounds read in archive_read_format_rar_read_header.
network
low complexity
libarchive CWE-193
7.5
2017-01-24 CVE-2016-10160 Off-by-one Error vulnerability in multiple products
Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted PHAR archive with an alias mismatch.
network
low complexity
php netapp debian CWE-193
critical
9.8
2016-12-29 CVE-2015-8701 Off-by-one Error vulnerability in Qemu
QEMU (aka Quick Emulator) built with the Rocker switch emulation support is vulnerable to an off-by-one error.
local
low complexity
qemu CWE-193
6.5
2010-09-24 CVE-2010-1773 Off-by-one Error vulnerability in multiple products
Off-by-one error in the toAlphabetic function in rendering/RenderListMarker.cpp in WebCore in WebKit before r59950, as used in Google Chrome before 5.0.375.70, allows remote attackers to obtain sensitive information, cause a denial of service (memory corruption and application crash), or possibly execute arbitrary code via vectors related to list markers for HTML lists, aka rdar problem 8009118.
8.8
2004-11-23 CVE-2004-0346 Off-by-one Error vulnerability in Proftpd 1.2.7/1.2.8/1.2.9
Off-by-one buffer overflow in _xlate_ascii_write() in ProFTPD 1.2.7 through 1.2.9rc2p allows local users to gain privileges via a 1024 byte RETR command.
local
low complexity
proftpd CWE-193
7.8
2004-11-23 CVE-2004-0342 Off-by-one Error vulnerability in Wftpd PRO Server Project Wftpd PRO Server 3.21
WFTPD Pro Server 3.21 Release 1, with the XeroxDocutech option enabled, allows local users to cause a denial of service (crash) via a (1) MKD or (2) XMKD command that causes an absolute path of 260 characters to be used, which overwrites a cookie with a null character, possibly due to an off-by-one error.
local
low complexity
wftpd-pro-server-project CWE-193
5.5
2004-03-03 CVE-2004-0005 Off-by-one Error vulnerability in Gaim Project Gaim 0.75
Multiple buffer overflows in Gaim 0.75 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) octal encoding in yahoo_decode that causes a null byte to be written beyond the buffer, (2) octal encoding in yahoo_decode that causes a pointer to reference memory beyond the terminating null byte, (3) a quoted printable string to the gaim_quotedp_decode MIME decoder that causes a null byte to be written beyond the buffer, and (4) quoted printable encoding in gaim_quotedp_decode that causes a pointer to reference memory beyond the terminating null byte.
network
low complexity
gaim-project CWE-193
critical
9.8
2003-08-27 CVE-2003-0625 Off-by-one Error vulnerability in Hadrons Xfstt
Off-by-one error in certain versions of xfstt allows remote attackers to read potentially sensitive memory via a malformed client request in the connection handshake, which leaks the memory in the server's response.
network
low complexity
hadrons CWE-193
7.5
2003-08-27 CVE-2003-0466 Off-by-one Error vulnerability in multiple products
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU, or (8) RNTO.
network
low complexity
wuftpd redhat apple sun freebsd netbsd openbsd CWE-193
critical
9.8
2003-08-18 CVE-2003-0252 Off-by-one Error vulnerability in Linux-Nfs Nfs-Utils
Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain RPC requests to mountd that do not contain newlines.
network
low complexity
linux-nfs CWE-193
critical
9.8