A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.
182 vulnerabilities with CWE-193
CVE-2026-41502
HIGH
BACnet Stack: Off-by-One Out-of-Bounds Read in ReadPropertyMultiple Object ID Decoder
CVSS 7.5
CVE-2026-40254
MEDIUM
FreeRDP: contains_dotdot() off-by-one allows drive channel path traversal via terminal ..
CVSS 4.2
CVE-2026-6861
MEDIUM
Emacs: emacs: memory corruption vulnerability when processing svg css
CVSS 6.1
CVE-2026-40312
MEDIUM
ImageMagick: Off-by-One in MSL decoder could result in crash
CVSS 6.2
CVE-2026-32605
HIGH
Nimiq: Remote crash via off-by-one signer bounds check in proposal buffer
CVSS 7.5
CVE-2026-33997
MEDIUM
Moby: Off-by-one error in plugin privilege validation
CVSS 6.8
CVE-2026-5123
LOW
osrg GoBGP bgp.go DecodeFromBytes off-by-one
CVSS 3.7
CVE-2026-22593
HIGH
EVerest has off-by-one stack buffer overflow in IsoMux certificate filename parsing
CVSS 8.4
CVE-2026-4887
MEDIUM
Gimp: gimp:memory disclosure and denial of service via specially crafted pcx image
CVSS 6.1
CVE-2026-34085
MEDIUM
Fontconfig < 2.17.1 - Out-of-Bounds Access
CVSS 5.9
CVE-2026-28520
HIGH
arduino-TuyaOpen WiFiMulti Single-Byte Buffer Overflow Remote Code Execution
CVSS 8.4
CVE-2026-31988
MEDIUM
yauzl 3.2.0 - DoS
CVSS 5.3
CVE-2026-26309
MEDIUM
Envoy <1.37.1 - Memory Corruption
CVSS 5.3
CVE-2026-25989
HIGH
ImageMagick <7.1.2-15/6.9.13-40 - DoS
CVSS 7.5
CVE-2026-2703
LOW
xlnt-community xlnt <=1.6.1 - Memory Corruption
CVSS 3.3
CVE-2026-21870
MEDIUM
BACnet Protocol Stack <1.5.0.rc2 - Buffer Overflow
CVSS 5.5
CVE-2026-23951
MEDIUM
SumatraPDF - Buffer Overflow
CVSS 5.5
CVE-2026-21504
MEDIUM
Color Iccdev < 2.3.1.2 - Out-of-Bounds Write
CVSS 6.6
CVE-2026-21494
MEDIUM
Color Iccdev < 2.3.1.2 - Buffer Overflow
CVSS 6.1
CVE-2026-21491
MEDIUM
Color Iccdev < 2.3.1.2 - Buffer Overflow
CVSS 6.1
CVE-2026-21490
MEDIUM
Color Iccdev < 2.3.1.2 - Buffer Overflow
CVSS 6.1
CVE-2025-71161
MEDIUM
Linux kernel - DoS
CVSS 5.5
CVE-2025-71087
MEDIUM
Linux kernel - Memory Corruption
CVSS 5.5
CVE-2025-11215
MEDIUM
Google Chrome <141.0.7390.54 - Memory Corruption
CVSS 4.3
CVE-2025-4582
HIGH
RTI Connext Professional < 6.1.2.26 - Buffer Over-read
CVSS 7.1
Details
Vulnerabilities
182