A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.
Volume of CVEs assigned to CWE-193 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
216 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3156HIGH Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line arg | Jan 26, 2021 | 7.8 | 99 | YES | YES |
CVE-2003-0466CRITICAL Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 throug | Aug 27, 2003 | 9.8 | 81 | NO | YES |
CVE-2021-23017HIGH A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in | Jun 1, 2021 | 7.7 | 65 | NO | YES |
CVE-2023-44444HIGH GIMP PSP File Parsing Off-By-One Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User i | May 3, 2024 | 7.8 | 54 | NO | NO |
CVE-2023-28709HIGH The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector set | May 22, 2023 | 7.5 | 53 | NO | NO |
CVE-2001-0609CRITICAL Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed ident reply that is passed to the syslog f | Aug 2, 2001 | 9.8 | 50 | NO | YES |
CVE-2002-0083CRITICAL Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges. | Mar 15, 2002 | 9.8 | 48 | NO | YES |
CVE-2018-8828CRITICAL A Buffer Overflow issue was discovered in Kamailio before 4.4.7, 5.0.x before 5.0.6, and 5.1.x before 5.1.2. A specially crafted REGISTER message with a malformed branch or From ta | Mar 20, 2018 | 9.8 | 44 | NO | NO |
CVE-2026-53309CRITICAL In the Linux kernel, the following vulnerability has been resolved:
ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison
The local-vs-remote region comparison loop | Jun 26, 2026 | 9.8 | 42 | NO | NO |
CVE-2026-58014HIGH A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This f | Jun 30, 2026 | 8.6 | 38 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.