CWE-369— Divide By Zero
The product divides a value by zero.— MITRE CWE catalog
468 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-369page 1 of 10
- CVE-2004-0804MEDIUMCVSS v2 4.3EG 4.32004-11-03
Vulnerability in tif_dirread.c for libtiff allows remote attackers to cause a denial of service (application crash) via a TIFF image that causes a divide-by-zero error when the number of row bytes is zero, a different vulnerability than CV…
- CVE-2006-5939HIGHCVSS v2 7.8EG 7.82006-11-16
Grisoft AVG Anti-Virus before 7.1.407 allows remote attackers to cause a denial of service (crash) via a crafted DOC file that triggers a divide-by-zero error. NOTE: some of these details are obtained from third party information.
- CVE-2007-2237MEDIUMCVSS 5.5EG 5.52007-06-06
Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, which triggers a divide-by-zero error.
- CVE-2007-2723MEDIUMCVSS 5.5EG 5.52007-05-16
Media Player Classic 6.4.9.0 allows user-assisted remote attackers to cause a denial of service (web browser crash) via an "empty" .MPA file, which triggers a divide-by-zero error.
- CVE-2007-3268HIGHCVSS 7.5EG 7.52007-07-18
The TFTP implementation in IBM Tivoli Provisioning Manager for OS Deployment 5.1 before Fix Pack 3 allows remote attackers to cause a denial of service (rembo.exe crash and multiple service outage) via a read (RRQ) request with an invalid …
- CVE-2009-1887MEDIUMCVSS v2 5.0EG 5.02009-06-26
agent/snmp_agent.c in snmpd in net-snmp 5.0.9 in Red Hat Enterprise Linux (RHEL) 3 allows remote attackers to cause a denial of service (daemon crash) via a crafted SNMP GETBULK request that triggers a divide-by-zero error. NOTE: this vul…
- CVE-2010-4165MEDIUMCVSS v2 4.9EG 4.92010-11-22
The do_tcp_setsockopt function in net/ipv4/tcp.c in the Linux kernel before 2.6.37-rc2 does not properly restrict TCP_MAXSEG (aka MSS) values, which allows local users to cause a denial of service (OOPS) via a setsockopt call that specifie…
- CVE-2011-1012MEDIUMCVSS v2 4.9EG 4.92011-03-01
The ldm_parse_vmdb function in fs/partitions/ldm.c in the Linux kernel before 2.6.38-rc6-git6 does not validate the VBLK size value in the VMDB structure in an LDM partition table, which allows local users to cause a denial of service (div…
- CVE-2012-0207HIGHCVSS 7.5EG 7.52012-05-17
The igmp_heard_query function in net/ipv4/igmp.c in the Linux kernel before 3.2.1 allows remote attackers to cause a denial of service (divide-by-zero error and panic) via IGMP packets.
- CVE-2014-0142MEDIUMCVSS 5.5EG 5.52017-08-10
QEMU, possibly before 2.0.0, allows local users to cause a denial of service (divide-by-zero error and crash) via a zero value in the (1) tracks field to the seek_to_sector function in block/parallels.c or (2) extent_size field in the boch…
- CVE-2014-8130MEDIUMCVSS 6.5EG 6.52018-03-12
The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image that is mishandled by the…
- CVE-2015-3418HIGHCVSS 7.5EG 7.52016-12-13
The ProcPutImage function in dix/dispatch.c in X.Org Server (aka xserver and xorg-server) before 1.16.4 allows attackers to cause a denial of service (divide-by-zero and crash) via a zero-height PutImage request.
- CVE-2015-7513MEDIUMCVSS 6.5EG 6.52016-02-08
arch/x86/kvm/x86.c in the Linux kernel before 4.4 does not reset the PIT counter values during state restoration, which allows guest OS users to cause a denial of service (divide-by-zero error and host OS crash) via a zero value, related t…
- CVE-2015-8504MEDIUMCVSS 6.5EG 6.52017-04-11
Qemu, when built with VNC display driver support, allows remote attackers to cause a denial of service (arithmetic exception and application crash) via crafted SetPixelFormat messages from a client.
- CVE-2016-10053MEDIUMCVSS 5.5EG 5.52017-03-23
The WriteTIFFImage function in coders/tiff.c in ImageMagick before 6.9.5-8 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted file.
- CVE-2016-10219MEDIUMCVSS 5.5EG 5.52017-04-03
The intersect function in base/gxfill.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted file.
- CVE-2016-10266MEDIUMCVSS 5.5EG 5.52017-03-24
LibTIFF 4.0.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image, related to libtiff/tif_read.c:351:22.
- CVE-2016-10267MEDIUMCVSS 5.5EG 5.52017-03-24
LibTIFF 4.0.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image, related to libtiff/tif_ojpeg.c:816:8.
- CVE-2016-10506MEDIUMCVSS 6.5EG 6.52017-08-30
Division-by-zero vulnerabilities in the functions opj_pi_next_cprl, opj_pi_next_pcrl, and opj_pi_next_rpcl in pi.c in OpenJPEG before 2.2.0 allow remote attackers to cause a denial of service (application crash) via crafted j2k files.
- CVE-2016-3622MEDIUMCVSS 6.5EG 6.52016-10-03
The fpAcc function in tif_predict.c in the tiff2rgba tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted TIFF image.
- CVE-2016-3623HIGHCVSS 7.5EG 7.52016-10-03
The rgb2ycbcr tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (divide-by-zero) by setting the (1) v or (2) h parameter to 0.
- CVE-2016-4797MEDIUMCVSS 5.5EG 5.52017-02-03
Divide-by-zero vulnerability in the opj_tcd_init_tile function in tcd.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (application crash) via a crafted jp2 file. NOTE: this issue exists because of an incorre…
- CVE-2016-5323HIGHCVSS 7.5EG 7.52017-01-20
The _TIFFFax3fillruns function in libtiff before 4.0.6 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted Tiff image.
- CVE-2016-6505MEDIUMCVSS 5.9EG 5.92016-08-06
epan/dissectors/packet-packetbb.c in the PacketBB dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted packet.
- CVE-2016-7499MEDIUMCVSS 5.5EG 5.52017-02-15
The sbr_make_f_master function in aacsbr.c in Libav 11.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted mp3 file.
- CVE-2016-7530MEDIUMCVSS 6.5EG 6.52017-04-20
The quantum handling code in ImageMagick allows remote attackers to cause a denial of service (divide-by-zero error or out-of-bounds write) via a crafted file.
- CVE-2016-8667MEDIUMCVSS 6.0EG 6.02016-11-04
The rc4030_write function in hw/dma/rc4030.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (divide-by-zero error and QEMU process crash) via a large interval timer reload value.
- CVE-2016-8669MEDIUMCVSS 6.0EG 6.02016-11-04
The serial_update_parameters function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (divide-by-zero error and QEMU process crash) via vectors involving a value of divider…
- CVE-2016-8691MEDIUMCVSS 5.5EG 5.52017-02-15
The jpc_dec_process_siz function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.4 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted XRsiz value in a BMP image to the imginfo …
- CVE-2016-8692MEDIUMCVSS 5.5EG 5.52017-02-15
The jpc_dec_process_siz function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.4 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted YRsiz value in a BMP image to the imginfo …
- CVE-2016-8697MEDIUMCVSS 5.5EG 5.52017-01-31
The bm_new function in bitmap.h in potrace before 1.13 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a crafted BMP image.
- CVE-2016-9112HIGHCVSS 7.5EG 7.52016-10-29
Floating Point Exception (aka FPE or divide by zero) in opj_pi_next_cprl function in openjp2/pi.c:523 in OpenJPEG 2.1.2.
- CVE-2016-9265MEDIUMCVSS 5.5EG 5.52017-03-23
The printMP3Headers function in listmp3.c in Libming 0.4.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted mp3 file.
- CVE-2016-9921MEDIUMCVSS 6.5EG 6.52016-12-23
Quick emulator (Qemu) built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to a divide by zero issue. It could occur while copying VGA data when cirrus graphics mode was set to be VGA. A privileged user inside guest could use…
- CVE-2016-9922MEDIUMCVSS 5.5EG 5.52017-03-27
The cirrus_do_copy function in hw/display/cirrus_vga.c in QEMU (aka Quick Emulator), when cirrus graphics mode is VGA, allows local guest OS privileged users to cause a denial of service (divide-by-zero error and QEMU process crash) via ve…
- CVE-2016-9960MEDIUMCVSS 5.5EG 5.52017-06-06
game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash).
- CVE-2017-0603MEDIUMCVSS 4.7EG 4.72017-05-12
A denial of service vulnerability in libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as Moderate because it requires an uncommon device configurat…
- CVE-2017-0857HIGHCVSS 7.5EG 7.52017-11-16
Another vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-65122447.
- CVE-2017-1000414HIGHCVSS 7.5EG 7.52018-01-25
ImpulseAdventure JPEGsnoop version 1.7.5 is vulnerable to a division by zero in the JFIF decode handling resulting denial of service.
- CVE-2017-11332MEDIUMCVSS 5.5EG 5.52017-07-31
The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted wav file.
- CVE-2017-11359MEDIUMCVSS 5.5EG 5.52017-07-31
The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted snd file, during conversion to a wav file.
- CVE-2017-11464HIGHCVSS 7.8EG 7.82017-07-19
A SIGFPE is raised in the function box_blur_line of rsvg-filter.c in GNOME librsvg 2.40.17 during an attempted parse of a crafted SVG file, because of incorrect protection against division by zero.
- CVE-2017-11546MEDIUMCVSS 5.5EG 5.52017-07-31
The insert_note_steps function in readmidi.c in TiMidity++ 2.14.0 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted mid file. NOTE: a crash might be relevant when using the --ba…
- CVE-2017-11720CRITICALCVSS 9.8EG 9.82017-07-28
There is a division-by-zero vulnerability in LAME 3.99.5, caused by a malformed input file.
- CVE-2017-12924MEDIUMCVSS 6.5EG 6.52017-08-28
CDirVector::GetTable in dirfunc.hxx in libfpx 1.3.1_p6 allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted fpx image.
- CVE-2017-14106MEDIUMCVSS 5.5EG 5.52017-09-01
The tcp_disconnect function in net/ipv4/tcp.c in the Linux kernel before 4.12 allows local users to cause a denial of service (__tcp_select_window divide-by-zero error and system crash) by triggering a disconnect within a certain tcp_recvm…
- CVE-2017-14249MEDIUMCVSS 6.5EG 6.52017-09-11
ImageMagick 7.0.6-8 Q16 mishandles EOF checks in ReadMPCImage in coders/mpc.c, leading to division by zero in GetPixelCacheTileSize in MagickCore/cache.c, allowing remote attackers to cause a denial of service via a crafted file.
- CVE-2017-14634MEDIUMCVSS 6.5EG 6.52017-09-21
In libsndfile 1.0.28, a divide-by-zero error exists in the function double64_init() in double64.c, which may lead to DoS when playing a crafted audio file.
- CVE-2017-15025MEDIUMCVSS 5.5EG 5.52017-10-05
decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted ELF…
- CVE-2017-15266MEDIUMCVSS 5.5EG 5.52017-10-11
In GNU Libextractor 1.4, there is a Divide-By-Zero in EXTRACTOR_wav_extract_method in wav_extractor.c via a zero sample rate.
Map vulnerabilities like CWE-369 to your infrastructure
EchelonGraph correlates every CVE — across CWE-369 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →