CWE-193: Off-by-one Error
A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.
105 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-79148 — Off-by-one error in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social enginee
- CVE-2024-10442 — Off-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066, 1.2.2-0
- CVE-2024-51554 — off-by-one-error
- CVE-2026-65927 — Apache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access control
- CVE-2026-28520 — arduino-TuyaOpen WiFiMulti Single-Byte Buffer Overflow Remote Code Execution
- CVE-2025-43971 — An issue was discovered in GoBGP before 3.35.0. pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value
- CVE-2026-22593 — EVerest has off-by-one stack buffer overflow in IsoMux certificate filename parsing
- CVE-2026-86297 — D-Link DIR-605 L2TP Control Message tunnel.c tunnel_set_params off-by-one
- CVE-2026-49127 — Music Player Daemon < 0.24.11 Stack Buffer Overflow via pcm_unpack_24be
- CVE-2006-10003 — XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack
- CVE-2026-41502 — BACnet Stack: Off-by-One Out-of-Bounds Read in ReadPropertyMultiple Object ID Decoder
- CVE-2024-57259 — sqfs_search_dir in Das U-Boot before 2025.01-rc1 exhibits an off-by-one error and resultant heap memory corruption for s
- CVE-2026-31988 — yauzl 3.2.0 - Denial of Service via Off-by-One Error in NTFS Timestamp Parser
- CVE-2025-43973 — An issue was discovered in GoBGP before 3.35.0. pkg/packet/rtr/rtr.go does not verify that the input length corresponds
- CVE-2026-21504 — Heap Buffer Overflow in iccDEV ToneMap Parser
- CVE-2026-54410 — nanoMODBUS Off-by-One Buffer Overflow in recv_msg_header() via Crafted MBAP Length Field
- CVE-2025-54349 — In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.
- CVE-2026-5123 — osrg GoBGP bgp.go DecodeFromBytes off-by-one
- CVE-2026-12413 — IKEv2 Denial of Service via malformed fragmentation
- CVE-2026-7831 — UltraVNC viewer off-by-one stack overflow in ServerInit desktop name parsing
Recently published
- CVE-2026-86297 — D-Link DIR-605 L2TP Control Message tunnel.c tunnel_set_params off-by-one
- CVE-2026-81738 — OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write
- CVE-2026-57160 — PJSIP: SIP message header buffer overflow
- CVE-2026-85454 — MOOS core-moos through 10.4.0 Off-by-One Buffer Overflow in Serial Telegram Handling
- CVE-2026-14368 — Off-by-one out-of-bounds NUL write in Zephyr LwM2M JSON string parser
- CVE-2026-46369 — Nimiq: Validity store off by one error
- CVE-2026-65927 — Apache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access control
- CVE-2026-79148 — Off-by-one error in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social enginee
- CVE-2026-68767 — hashcat through 7.1.2 Off-by-One Out-of-Bounds Heap Write in fgetl()
- CVE-2026-63387 — Libevent: Off-by-one stack buffer overflow in dnsname_to_labels via crafted DNS server response
- CVE-2026-55564 — FreeRDP: Out-of-bounds read in glyph_cache_get via crafted glyph fragments
- CVE-2026-71391 — Off-by-One Error in GNU Emacs for Android
- CVE-2026-11771 — OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the
- CVE-2026-44687 — Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN
- CVE-2026-58380 — Gimp: gimp: stack buffer overflow in pnmscanner_gettoken()
- CVE-2026-12413 — IKEv2 Denial of Service via malformed fragmentation
- CVE-2026-7831 — UltraVNC viewer off-by-one stack overflow in ServerInit desktop name parsing
- CVE-2026-44042 — UltraVNC repeater wi_uudecode off-by-one in base64 decode boundary check
- CVE-2026-58014 — Glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list"
- CVE-2026-58374 — In hostapd before 2.12, a missing bounds check in AP-mode Wi-Fi 7 (IEEE 802.11be) Multi-Link Operation (MLO) association