CWE-369— Divide By Zero
The product divides a value by zero.— MITRE CWE catalog
482 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-369page 1 of 10
- CVE-2026-24826CRITICALCVSS 10.0EG 10.02026-01-27
Out-of-bounds Write, Divide By Zero, NULL Pointer Dereference, Use of Uninitialized Resource, Out-of-bounds Read, Reachable Assertion vulnerability in cadaver turso3d.This issue affects .
- CVE-2021-32494CRITICALCVSS 10.0EG 10.02023-07-07
Radare2 has a division by zero vulnerability in Mach-O parser's rebase_buffer function. This allow attackers to create malicious inputs that can cause denial of service.
- CVE-2017-11720CRITICALCVSS 9.8EG 9.82017-07-28
There is a division-by-zero vulnerability in LAME 3.99.5, caused by a malformed input file.
- CVE-2020-20892HIGHCVSS 8.8EG 8.82021-09-20
An issue was discovered in function filter_frame in libavfilter/vf_lenscorrection.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts due to a division by zero.
- CVE-2025-4637HIGHCVSS 8.7EG 8.72025-05-14
Divide By Zero vulnerability in davisking dlib allows remote attackers to cause a denial of service via a crafted file. .This issue affects dlib: before <19.24.7.
- CVE-2026-37232HIGHCVSS 8.6EG 8.62026-06-01
An issue was discovered in OpenAirInterface5G 2.4.0 (nr-softmodem) in the E2SM-KPM RAN Function's PRB utilization metric calculation. The functions fill_RRU_PrbTotDl() and fill_RRU_PrbTotUl() in openair2/E2AP/RAN_FUNCTION/O-RAN/ran_func_kp…
- CVE-2024-26945HIGHCVSS 8.4EG 8.42024-05-01
In the Linux kernel, the following vulnerability has been resolved: crypto: iaa - Fix nr_cpus < nr_iaa case If nr_cpus < nr_iaa, the calculated cpus_per_iaa will be 0, which causes a divide-by-0 in rebalance_wq_table(). Make sure cpus_p…
- CVE-2023-3896HIGHCVSS 7.8EG 7.82023-08-07
Divide By Zero in vim/vim from 9.0.1367-1 to 9.0.1367-3
- CVE-2023-1127HIGHCVSS 7.8EG 7.82023-03-01
Divide By Zero in GitHub repository vim/vim prior to 9.0.1367.
- CVE-2023-0512HIGHCVSS 7.8EG 7.82023-01-30
Divide By Zero in GitHub repository vim/vim prior to 9.0.1247.
- CVE-2023-21789HIGHCVSS 7.8EG 7.82023-01-10
3D Builder Remote Code Execution Vulnerability
- CVE-2019-14535HIGHCVSS 7.8EG 7.82019-08-29
A divide-by-zero error exists in the SeekIndex function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1. As a result, an FPE can be triggered via a crafted WMV file.
- CVE-2019-14498HIGHCVSS 7.8EG 7.82019-08-29
A divide-by-zero error exists in the Control function of demux/caf.c in VideoLAN VLC media player 3.0.7.1. As a result, an FPE can be triggered via a crafted CAF file.
- CVE-2017-11464HIGHCVSS 7.8EG 7.82017-07-19
A SIGFPE is raised in the function box_blur_line of rsvg-filter.c in GNOME librsvg 2.40.17 during an attempted parse of a crafted SVG file, because of incorrect protection against division by zero.
- CVE-2017-7598HIGHCVSS 7.8EG 7.82017-04-09
tif_dirread.c in LibTIFF 4.0.7 might allow remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted image.
- CVE-2006-5939HIGHCVSS v2 7.8EG 7.82006-11-16
Grisoft AVG Anti-Virus before 7.1.407 allows remote attackers to cause a denial of service (crash) via a crafted DOC file that triggers a divide-by-zero error. NOTE: some of these details are obtained from third party information.
- CVE-2024-6135HIGHCVSS 7.6EG 7.62024-09-13
BT:Classic: Multiple missing buf length checks
- CVE-2024-4785HIGHCVSS 7.6EG 7.62024-08-19
BT: Missing Check in LL_CONNECTION_UPDATE_IND Packet Leads to Division by Zero
- CVE-2026-91955HIGHCVSS 7.5EG 7.52026-09-15
FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth and DesktopHeight values during GCC negotiation, allowing remote attackers to crash the server. Attackers can send crafted RDP packets with zero or oversized dimensions t…
- CVE-2026-53503HIGHCVSS 7.5EG 7.52026-07-31
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(<matrix>, <columns>, <should_normalize>) filter passes the user-controlled <columns> value to a C extension (thumbor/ext/filters/…
- CVE-2026-62431HIGHCVSS 7.5EG 7.52026-07-28
The logic to handle periodic Viridian STIMERs performs a division with an unchecked user-controlled divisor value, that can be set to zero to cause a #DE fault.
- CVE-2026-33593HIGHCVSS 7.5EG 7.52026-04-22
A client can trigger a divide by zero error leading to crash by sending a crafted DNSCrypt query.
- CVE-2026-35215HIGHCVSS 7.5EG 7.52026-04-17
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the sdl_desc() function does not validate the length of a decoded SDL descriptor from a slice packet. A zero-length descriptor …
- CVE-2026-5747HIGHCVSS 7.5EG 7.52026-04-08
An out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and aarch64 might allow a local guest user with root privileges to crash the Firecracker VMM process or potentially execute …
- CVE-2026-31884HIGHCVSS 7.5EG 7.52026-03-13
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, division by zero in MS-ADPCM and IMA-ADPCM decoders when nBlockAlign is 0, leading to a crash. In libfreerdp/codec/dsp.c, both ADPCM decoders use size % bloc…
- CVE-2026-25799HIGHCVSS 7.5EG 7.52026-02-24
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a logic error in YUV sampling factor validation allows an invalid sampling factor to bypass checks and…
- CVE-2025-65409HIGHCVSS 7.5EG 7.52025-12-30
A divide-by-zero in the encryption/decryption routines of GNU Recutils v1.9 allows attackers to cause a Denial of Service (DoS) via inputting an empty value as a password.
- CVE-2025-23321HIGHCVSS 7.5EG 7.52025-08-06
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause a divide by zero issue by issuing an invalid request. A successful exploit of this vulnerability might lead to denial of service.
- CVE-2025-54581HIGHCVSS 7.5EG 7.52025-07-30
vproxy is an HTTP/HTTPS/SOCKS5 proxy server. In versions 2.3.3 and below, untrusted data is extracted from the user-controlled HTTP Proxy-Authorization header and passed to Extension::try_from and flows into parse_ttl_extension where it is…
- CVE-2025-0317HIGHCVSS 7.5EG 7.52025-03-20
A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to upload and create a customized GGUF model file on the Ollama server. This can lead to a division by zero error in the ggufPadding function, causing the server to…
- CVE-2024-8063HIGHCVSS 7.5EG 7.52025-03-20
A divide by zero vulnerability exists in ollama/ollama version v0.3.3. The vulnerability occurs when importing GGUF models with a crafted type for `block_count` in the Modelfile. This can lead to a denial of service (DoS) condition when th…
- CVE-2024-56073HIGHCVSS 7.5EG 7.52024-12-15
An issue was discovered in FastNetMon Community Edition through 1.2.7. Zero-length templates for Netflow v9 allow remote attackers to cause a denial of service (divide-by-zero error and application crash).
- CVE-2024-21438HIGHCVSS 7.5EG 7.52024-03-12
Microsoft AllJoyn API Denial of Service Vulnerability
- CVE-2023-52313HIGHCVSS 7.5EG 7.52024-01-03
FPE in paddle.argmin and paddle.argmax in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.
- CVE-2023-52308HIGHCVSS 7.5EG 7.52024-01-03
FPE in paddle.amin in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.
- CVE-2023-52306HIGHCVSS 7.5EG 7.52024-01-03
FPE in paddle.lerp in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.
- CVE-2023-52305HIGHCVSS 7.5EG 7.52024-01-03
FPE in paddle.topk in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.
- CVE-2023-51107HIGHCVSS 7.5EG 7.52023-12-26
A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in functon compute_color() of jquant2.c. NOTE: this is disputed by the supplier because there was not reasonable evidence to determine the exi…
- CVE-2023-51106HIGHCVSS 7.5EG 7.52023-12-26
A floating point exception (divide-by-zero) vulnerability was discovered in mupdf 1.23.4 in function pnm_binary_read_image() of load-pnm.c when fz_colorspace_n returns zero.
- CVE-2023-51105HIGHCVSS 7.5EG 7.52023-12-26
A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function bmp_decompress_rle4() of load-bmp.c.
- CVE-2023-51104HIGHCVSS 7.5EG 7.52023-12-26
A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function pnm_binary_read_image() of load-pnm.c when span equals zero.
- CVE-2023-51103HIGHCVSS 7.5EG 7.52023-12-26
A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in the function fz_new_pixmap_from_float_data() of pixmap.c.
- CVE-2023-46849HIGHCVSS 7.5EG 7.52023-11-11
Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour which could cause an application crash, leading to a denial of service.
- CVE-2021-40211HIGHCVSS 7.5EG 7.52023-08-22
An issue was discovered with ImageMagick 7.1.0-4 via Division by zero in function ReadEnhMetaFile of coders/emf.c.
- CVE-2022-47525HIGHCVSS 7.5EG 7.52023-05-31
Fox-IT DataDiode (aka Fox DataDiode) 3.4.3 suffers from a Divide-by-Zero vulnerability in the packet parser. A remote attacker could leverage this vulnerability to cause a denial-of-service. Exploitation of this issue does not require user…
- CVE-2023-2839HIGHCVSS 7.5EG 7.52023-05-22
Divide By Zero in GitHub repository gpac/gpac prior to 2.2.2.
- CVE-2023-23109HIGHCVSS 7.5EG 7.52023-02-27
In crasm 1.8-3, invalid input validation, specific files passed to the command line application, can lead to a divide by zero fault in the function opdiv.
- CVE-2021-33654HIGHCVSS 7.5EG 7.52022-06-27
When performing the initialization operation of the Split operator, if a dimension in the input shape is 0, it will cause a division by 0 exception.
- CVE-2021-33653HIGHCVSS 7.5EG 7.52022-06-27
When performing the derivation shape operation of the SpaceToBatch operator, if there is a value of 0 in the parameter block_shape element, it will cause a division by 0 exception.
- CVE-2021-33652HIGHCVSS 7.5EG 7.52022-06-27
When the Reduce operator run operation is executed, if there is a value of 0 in the parameter axis_sizes element, it will cause a division by 0 exception.
Map vulnerabilities like CWE-369 to your infrastructure
EchelonGraph correlates every CVE — across CWE-369 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →