Skip to main content

Threats Tagged 'cwe-193'

View all threats tagged with 'cwe-193'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-193

Threats Tagged 'cwe-193'

Click on any threat for detailed analysis and mitigation recommendations

Off-by-one Error, Out-of-bounds Write vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6.

Join the discussion
0

Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p. The palette is allocated uninitialised, and only the entries a reader adds count as populated. The TGA reader stores pixel indexes without checking them against the colour map. i_gpix_p() rejects only an index greater than the count, so an index equal to it reads the first unpopulated entry, and getpixel() returns it. i_glin_p() skips any index at or beyond the count without writing that pixel to the caller's buffer. The palette-to-RGB conversion reads each row through an uninitialised buffer, so those pixels of the converted image hold prior heap contents. Reading an attacker-supplied image through Imager->read() and then fetching its pixels or converting it to RGB discloses process heap memory.

Join the discussion

CVE-2026-81396 is a stack-based buffer overflow vulnerability in Microsoft Office Excel within Microsoft 365 Apps for Enterprise. This flaw allows an unauthorized attacker to execute code locally on the affected system. The vulnerability has a high severity rating with a CVSS score of 7.8. An official fix is available from Microsoft, and the vendor manages remediation for this cloud-hosted service. No known exploits are reported in the wild at this time.

Join the discussion

Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.

Join the discussion
0

A vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects the function tunnel_set_params of the file progs.gpl/pppd.alpha/l2tp/tunnel.c of the component L2TP Control Message Parser. Such manipulation of the argument peer_hostname  leads to off-by-one. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit is publicly available and might be used.

Join the discussion

CVE-2026-57160 is an off-by-one buffer overflow vulnerability in the pjsip multimedia communication library's pjproject component. The flaw occurs in the function pjsip_generic_array_hdr_print() which serializes generic array headers in SIP messages. Under certain output buffer boundary conditions, the function may write one byte beyond the allocated buffer. This vulnerability mainly affects applications that parse and re-serialize incoming SIP requests, such as proxies, SBCs, or B2BUAs. Although the out-of-bounds write is limited to a single byte and code execution or information disclosure has not been demonstrated, it represents a medium severity risk. The issue has been patched in commit d6a0e7f.

Join the discussion

An off-by-one error vulnerability in Apache Tomcat's rewrite valve processing causes the rewrite to restart at the second rule instead of the first. This affects multiple versions of Apache Tomcat, including 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.0.M1 through 9.0.120, and some older 8.5.x versions. The issue is fixed in versions 11.0.25, 10.1.58, and 9.0.121.

Join the discussion

A vulnerability in the Nimiq blockchain Rust implementation (up to version 1.5.0) causes a validity store off-by-one error that allows replaying signed transactions within a specific block window, resulting in double updates to sender and recipient balances. This flaw is fixed in version 1.5.1.

Join the discussion

Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Join the discussion
0

GNU Emacs for Android contains an off-by-one error in its TrueType variable font parser that allows a crafted font file to trigger a heap-based out-of-bounds read. This vulnerability can be exploited by delivering a malicious font via email, the Emacs Web Wowser (EWW), or documents with custom faces, potentially exposing heap memory contents and aiding in bypassing ASLR. The issue was fixed in a specific commit, but no explicit patch or affected versions are provided in the data.

Join the discussion

Showing 1 to 10 of 36 results

Filters:Tag: cwe-193
Page 1 of 4
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses