CWE-193: CWE-193

42
Total CVEs
6
Critical
18
High
7.0
Avg CVSS

Yearly Trend

2026
2
2025
15
2024
18
2023
4
2022
2

Top Affected Vendors

1 Linux 25
2 Debian 3
3 Osrg 2
4 Netatalk 1
5 Vyperlang 1
6 Bacnetstack 1
7 Google 1
8 Memcached 1
9 Synology 1
10 Accusoft 1

All CWE-193 CVEs (42)

CVE-2024-10442
10.0

This critical vulnerability allows remote attackers to execute arbitrary code on affected Synology systems due to an off-by-one error in the transmiss...

Mar 19, 2025
CVE-2024-38441
9.8

This CVE describes a heap-based buffer overflow vulnerability in Netatalk's AFP service due to an off-by-one error when processing file/directory name...

Jun 16, 2024
CVE-2023-46853
9.8

This CVE describes an off-by-one error in Memcached proxy mode when processing requests with newline characters. Attackers can exploit this to cause b...

Oct 27, 2023
CVE-2021-31875
9.8

CVE-2021-31875 is an off-by-one heap-based buffer overflow vulnerability in mjs_json_parse function of Cesanta MongooseOS mJS 1.26. A malicious JSON s...

Apr 29, 2021
CVE-2024-51554
9.1

CVE-2024-51554 is a default credential vulnerability in ABB ASPECT products on Linux that allows attackers to gain unauthorized access using publicly ...

Dec 5, 2024
CVE-2021-4070
9.1

CVE-2021-4070 is an off-by-one error in v2ray-core that can lead to memory corruption and potential remote code execution. This affects all users runn...

Feb 23, 2022
CVE-2025-43971
8.6

This vulnerability in GoBGP allows attackers to trigger a denial of service by sending specially crafted BGP packets with a zero value for softwareVer...

Apr 21, 2025
CVE-2024-57990
7.8

This CVE describes an off-by-one vulnerability in the mt7925 WiFi driver in the Linux kernel that could allow an attacker with local access to cause a...

Feb 27, 2025
CVE-2024-49880
7.8

This CVE describes an off-by-one buffer overflow vulnerability in the Linux kernel's ext4 filesystem resize functionality. The flaw in alloc_flex_gd()...

Oct 21, 2024
CVE-2024-47682
7.8

This CVE describes an off-by-one buffer overflow vulnerability in the Linux kernel's SCSI subsystem. When a device returns a specific SCSI page with l...

Oct 21, 2024
CVE-2024-46852
7.8

A Linux kernel vulnerability in the CMA heap fault handler allows an attacker to bypass boundary checks and potentially insert arbitrary pages into me...

Sep 27, 2024
CVE-2024-43852
7.8

This CVE describes an off-by-one buffer overflow vulnerability in the Linux kernel's LTC2991 hardware monitoring driver. An attacker with local access...

Aug 17, 2024
CVE-2022-48732
7.8

This CVE describes an off-by-one buffer boundary checking vulnerability in the Nouveau DRM driver in the Linux kernel. When parsing BIOS initializatio...

Jun 20, 2024
CVE-2022-48672
7.8

This is a buffer overflow vulnerability in the Linux kernel's device tree unflattening function. An attacker could exploit this to cause a kernel pani...

May 3, 2024
CVE-2024-26995
7.8

This CVE-2024-26995 is an off-by-one vulnerability in the Linux kernel's USB Type-C Power Delivery (PD) subsystem that can cause incorrect power negot...

May 1, 2024
CVE-2021-47046
7.8

This CVE describes an off-by-one buffer overflow vulnerability in the Linux kernel's AMD display driver. The flaw allows reading one byte beyond the a...

Feb 28, 2024
CVE-2022-33064
7.8

CVE-2022-33064 is an off-by-one buffer overflow vulnerability in Libsndfile's WAV file header parsing. Attackers can exploit this by crafting maliciou...

Jul 18, 2023
CVE-2024-36136
7.5

An off-by-one error in WLInfoRailService in Ivanti Avalanche allows remote unauthenticated attackers to crash the service, causing denial of service. ...

Aug 14, 2024
CVE-2023-46247
7.5

This vulnerability in Vyper smart contract language causes incorrect memory allocation for large arrays, potentially leading to memory corruption. It ...

Dec 13, 2023
CVE-2023-28709
7.5

This vulnerability allows attackers to bypass request size limits in Apache Tomcat by submitting exactly maxParameterCount query parameters, potential...

May 22, 2023
CVE-2024-57259
7.1

An off-by-one error in Das U-Boot's squashfs directory listing function (sqfs_search_dir) causes heap memory corruption when processing paths. This vu...

Feb 18, 2025
CVE-2024-56663
7.1

This is an off-by-one vulnerability in the Linux kernel's nl80211 WiFi subsystem that allows out-of-bounds memory access when handling Multi-Link Oper...

Dec 27, 2024
CVE-2024-49862
7.1

This CVE-2024-49862 is an off-by-one buffer access vulnerability in the Linux kernel's Intel RAPL (Running Average Power Limit) power capping subsyste...

Oct 21, 2024
CVE-2022-23400
7.1

A stack-based buffer overflow vulnerability in Accusoft ImageGear's PSD file parser allows attackers to cause denial of service or potentially leak in...

May 3, 2022
CVE-2025-43973
6.8

A buffer boundary error in GoBGP's RTR message processing allows attackers to cause denial of service or potentially execute arbitrary code by sending...

Apr 21, 2025
CVE-2026-21870
5.5

This CVE describes an off-by-one stack-based buffer overflow in the BACnet Protocol Stack library's ubasic interpreter. When processing string literal...

Feb 13, 2026
CVE-2025-71161
5.5

A vulnerability in the Linux kernel's dm-verity subsystem allows denial-of-service attacks through recursive forward error correction. Attackers can c...

Jan 23, 2026
CVE-2022-50428
5.5

This CVE-2022-50428 is an off-by-one error in the Linux kernel's ext4 filesystem fast-commit journaling feature that could cause kernel crashes or dat...

Oct 1, 2025
CVE-2023-53397
5.5

This CVE describes an off-by-one error in the Linux kernel's modpost component, specifically in the is_executable_section() function. The vulnerabilit...

Sep 18, 2025
CVE-2025-38600
5.5

This CVE describes an off-by-one buffer overflow vulnerability in the mt7925 WiFi driver in the Linux kernel. An attacker could potentially cause a ke...

Aug 19, 2025
CVE-2025-23150
5.5

A Linux kernel vulnerability in the ext4 filesystem's do_split function allows an off-by-one error that can lead to out-of-bounds memory access and us...

May 1, 2025
CVE-2025-37893
5.5

A Linux kernel vulnerability in the LoongArch BPF JIT compiler causes an off-by-one error in build_prologue() when handling BPF programs with tailcall...

Apr 18, 2025
CVE-2025-21813
5.5

A race condition in the Linux kernel timer migration subsystem can cause multiple top-level timer groups to exist, defeating the single idle migrator ...

Feb 27, 2025
CVE-2022-49365
5.5

This is an off-by-one buffer overflow vulnerability in the AMD GPU driver for Linux kernels. It allows local attackers to potentially crash the system...

Feb 26, 2025
CVE-2022-49077
5.5

A Linux kernel vulnerability where mremap() with old_size=0 triggers unnecessary invalidate_range_start/end calls, causing a WARN in KVM's mmu_notifie...

Feb 26, 2025
CVE-2024-56720
5.5

This CVE addresses multiple bugs in the Linux kernel's BPF subsystem, specifically in the bpf_msg_pop_data function used for socket map operations. Th...

Dec 29, 2024
CVE-2024-36957
5.5

This CVE describes an off-by-one read vulnerability in the Linux kernel's octeontx2-af driver. An attacker with local access could exploit this to rea...

May 30, 2024
CVE-2024-36025
5.5

This CVE describes an off-by-one buffer overflow vulnerability in the qla2xxx SCSI driver in the Linux kernel. An attacker with local access could pot...

May 30, 2024
CVE-2021-47373
5.5

This CVE describes an off-by-one error in the Linux kernel's GIC-V3 interrupt controller that could cause a memory leak when virtual CPU (VPE) allocat...

May 21, 2024
CVE-2024-48854
5.3

An off-by-one error in the TIFF image codec in QNX SDP versions 8.0, 7.1, and 7.0 could allow an unauthenticated attacker to cause information disclos...

Jan 14, 2025
CVE-2024-53149
4.6

This vulnerability is an off-by-one error in the Linux kernel's UCSI (USB Type-C Connector System Software Interface) driver for PMIC Glink. It causes...

Dec 24, 2024
CVE-2025-11215
4.3

This CVE describes an off-by-one error in Chrome's V8 JavaScript engine that allows a remote attacker to read memory outside the intended buffer bound...

Nov 6, 2025

About CWE-193 (CWE-193)

Our database tracks 42 CVEs classified as CWE-193, with 6 rated critical and 18 rated high severity. The average CVSS score for CWE-193 vulnerabilities is 7.0.

External reference: View CWE-193 on MITRE CWE →

Monitor CWE-193 Vulnerabilities

Get alerted when new CWE-193 CVEs affect your infrastructure.

Start Monitoring Free