Show filters
37 Total Results
Displaying 11-20 of 37
Sort by:
Attacker Value
Unknown
CVE-2020-10062
Disclosure Date: May 25, 2020 (last updated February 21, 2025)
An off-by-one error in the Zephyr project MQTT packet length decoder can result in memory corruption and possible remote code execution. NCC-ZEP-031 This issue affects: zephyrproject-rtos zephyr version 2.2.0 and later versions.
0
Attacker Value
Unknown
CVE-2019-19721
Disclosure Date: May 15, 2020 (last updated February 21, 2025)
An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows remote attackers to cause a denial of service (memory corruption) via a crafted image file. NOTE: this may be related to the SDL_Image product.
0
Attacker Value
Unknown
CVE-2019-12521
Disclosure Date: April 15, 2020 (last updated February 21, 2025)
An issue was discovered in Squid through 4.7. When Squid is parsing ESI, it keeps the ESI elements in ESIContext. ESIContext contains a buffer for holding a stack of ESIElements. When a new ESIElement is parsed, it is added via addStackElement. addStackElement has a check for the number of elements in this buffer, but it's off by 1, leading to a Heap Overflow of 1 element. The overflow is within the same structure so it can't affect adjacent memory blocks, and thus just leads to a crash while processing.
0
Attacker Value
Unknown
CVE-2020-11765
Disclosure Date: April 14, 2020 (last updated February 21, 2025)
An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Classifier, leading to an out-of-bounds read.
0
Attacker Value
Unknown
CVE-2020-3840
Disclosure Date: February 27, 2020 (last updated February 21, 2025)
An off by one issue existed in the handling of racoon configuration files. This issue was addressed through improved bounds checking. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1. Loading a maliciously crafted racoon configuration file may lead to arbitrary code execution.
0
Attacker Value
Unknown
CVE-2020-8443
Disclosure Date: January 30, 2020 (last updated February 21, 2025)
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to an off-by-one heap-based buffer overflow during the cleaning of crafted syslog msgs (received from authenticated remote agents and delivered to the analysisd processing queue by ossec-remoted).
0
Attacker Value
Unknown
CVE-2020-7044
Disclosure Date: January 16, 2020 (last updated February 21, 2025)
In Wireshark 3.2.x before 3.2.1, the WASSP dissector could crash. This was addressed in epan/dissectors/packet-wassp.c by using >= and <= to resolve off-by-one errors.
0
Attacker Value
Unknown
CVE-2020-6835
Disclosure Date: January 10, 2020 (last updated February 21, 2025)
An issue was discovered in Bftpd before 5.4. There is a heap-based off-by-one error during file-transfer error checking.
0
Attacker Value
Unknown
CVE-2014-8182
Disclosure Date: January 02, 2020 (last updated February 21, 2025)
An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages. If slapd was configured to use the dnssrv backend, an attacker could crash the service with crafted DNS responses.
0
Attacker Value
Unknown
CVE-2005-1268
Disclosure Date: August 05, 2005 (last updated February 22, 2025)
Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.
0