Cyber Resilience

CWE · MITRE source

CWE-193Off-by-one Error

Abstraction: Base · CVEs in our corpus: 221

A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.

Last updated: 22 August 2026 20:22 UTC

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • PR.PS-06
  • SA-11 Developer Testing and Evaluation
  • SA-15 Development Process, Standards, and Tools
  • SI-10 Information Input Validation
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V6.2.1

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2003-0466 9.99.80.78122003-08-27
CVE-2018-8828 8.99.80.30922018-03-20
CVE-2001-0609 8.59.80.18242001-08-02
CVE-2021-3156 KEV 8.57.80.99292021-01-26
CVE-2002-0083 8.49.80.14692002-03-15
CVE-2003-0252 8.49.80.15782003-08-18
CVE-2003-0356 8.29.80.09572003-06-09
CVE-2004-0005 8.29.80.11212004-03-03
CVE-2002-1816 8.19.80.08952002-12-31
CVE-2016-10160 8.19.80.07322017-01-24
CVE-2023-44444 8.17.80.56402024-05-03
CVE-2021-23017 8.07.70.53462021-06-01
CVE-2001-1496 7.99.80.04842001-12-31
CVE-2018-14599 7.99.80.04802018-08-24
CVE-2019-8268 7.99.80.03922019-03-08
CVE-2019-8272 7.99.80.03922019-03-08
CVE-2022-34970 7.99.80.03932022-08-04
CVE-2023-28709 7.97.50.49942023-05-22
CVE-2019-14532 7.79.80.02102019-08-02
CVE-2020-6835 7.79.80.02022020-01-10
CVE-2020-8443 7.79.80.02682020-01-30
CVE-2020-14510 7.79.80.02492020-08-25
CVE-2021-31875 7.79.80.02172021-04-29
CVE-2024-10442 7.710.00.01422025-03-19
CVE-2021-21938 7.69.80.01792022-04-14