VYPR

CWE-369

Divide By Zero

BaseDraftLikelihood: Medium

Description

The product divides a value by zero.

This weakness typically occurs when an unexpected value is provided to the product, or if an error occurs that is not properly detected. It frequently occurs in calculations involving physical dimensions such as size, length, width, and height.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (465)

page 19 of 24
  • CVE-2023-38672MedJul 26, 2023
    risk 0.24cvss 4.7epss 0.01

    FPE in paddle.trace in PaddlePaddle before 2.5.0. This flaw can cause a runtime crash and a denial of service.

  • CVE-2026-64951LowAug 12, 2026
    risk 0.23cvss 3.5epss 0.00

    A rogue Velociraptor client can upload a malformed sparse file such that if the GUI attempts to expand the file, a panic occurs which may crash the server process. The problem is a Divide by Zero bug in the ShouldPadFile() function.

  • CVE-2020-27773LowDec 4, 2020
    risk 0.22cvss 3.3epss 0.01

    A flaw was found in ImageMagick in MagickCore/gem-private.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned char` or division by zero. This would most likely lead…

  • CVE-2020-27765LowDec 4, 2020
    risk 0.22cvss 3.3epss 0.01

    A flaw was found in ImageMagick in MagickCore/segment.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. This would most likely lead to an impact to application availability, but could…

  • CVE-2020-27763LowDec 3, 2020
    risk 0.22cvss 3.3epss 0.01

    A flaw was found in ImageMagick in MagickCore/resize.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. This would most likely lead to an impact to application availability, but could…

  • CVE-2026-67302MedAug 1, 2026
    risk 0.21cvss 4.3epss 0.00

    FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a divide-by-zero vulnerability in the rdpecam camera redirection client. ecam_dev_process_start_streams_request() parses a server-controlled CAM_MEDIA_TYPE_DESCRIPTION from a StartStreamsRequest PDU but validates only…

  • CVE-2026-42443LowMay 12, 2026
    risk 0.21cvss 3.3epss 0.00

    NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an integer divide-by-zero exists in the UFS/UFS2 filesystem image parser in NanaZip. The vulnerability is triggered when opening a crafted UFS image where the superblock field fs_ipg (inodes per…

  • CVE-2026-21996LowMay 1, 2026
    risk 0.21cvss 3.3epss 0.00

    An unprivileged attacker can reliably trigger a crash of the dtrace process with a malicious ELF binary due to an integer Divide-by-Zero in Pbuild_file_symtab()

  • CVE-2026-3383LowMar 1, 2026
    risk 0.21cvss 3.3epss 0.00

    A weakness has been identified in ChaiScript up to 6.1.0. This affects the function chaiscript::Boxed_Number::go of the file include/chaiscript/dispatchkit/boxed_number.hpp. Executing a manipulation can lead to divide by zero. The attack requires local access. The exploit has…

  • CVE-2025-15564LowFeb 7, 2026
    risk 0.21cvss 3.3epss 0.00

    A vulnerability has been found in Mapnik up to 4.2.0. This vulnerability affects the function mapnik::detail::mod<...>::operator of the file src/value.cpp. The manipulation leads to divide by zero. The attack needs to be performed locally. The exploit has been disclosed to the…

  • CVE-2025-9649LowAug 29, 2025
    risk 0.21cvss 3.3epss 0.00

    A security vulnerability has been detected in appneta tcpreplay 4.5.1. Impacted is the function calc_sleep_time of the file send_packets.c. Such manipulation leads to divide by zero. An attack has to be approached locally. The exploit has been disclosed publicly and may be used.…

  • CVE-2023-3044LowJun 2, 2023
    risk 0.21cvss 3.3epss 0.00

    An excessively large PDF page size (found in fuzz testing, unlikely in normal PDF files) can result in a divide-by-zero in Xpdf's text extraction code. This is related to CVE-2022-30524, but the problem here is caused by a very large page size, rather than by a very large…

  • CVE-2023-25511LowApr 22, 2023
    risk 0.21cvss 3.3epss 0.00

    NVIDIA CUDA Toolkit for Linux and Windows contains a vulnerability in cuobjdump, where a division-by-zero error may enable a user to cause a crash, which may lead to a limited denial of service.

  • CVE-2022-41287LowDec 13, 2022
    risk 0.21cvss 3.3epss 0.00

    A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.8), Teamcenter Visualization V14.0 (All versions < V14.0.0.4), Teamcenter Visualization…

  • CVE-2020-14415LowAug 27, 2020
    risk 0.21cvss 3.3epss 0.00

    oss_write in audio/ossaudio.c in QEMU before 5.0.0 mishandles a buffer position.

  • CVE-2025-48754LowMay 24, 2025
    risk 0.19cvss 2.9epss 0.00

    In the memory_pages crate 0.1.0 for Rust, division by zero can occur.

  • CVE-2023-2662LowMay 11, 2023
    risk 0.19cvss 2.9epss 0.00

    In Xpdf 4.04 (and earlier), a bad color space object in the input PDF file can cause a divide-by-zero.

  • CVE-2025-55212LowAug 26, 2025
    risk 0.17cvss 3.7epss 0.01

    ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2, passing a geometry string containing only a colon (":") to montage -geometry leads GetGeometry() to set width/height to 0. Later,…

  • CVE-2025-23273LowSep 24, 2025
    risk 0.16cvss 2.5epss 0.00

    NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvJPEG where a local authenticated user may cause a divide by zero error by submitting a specially crafted JPEG file. A successful exploit of this vulnerability may lead to denial of service.

  • CVE-2026-10679LowJul 21, 2026
    risk 0.14cvss 3.3epss 0.00

    The DesignWare SPI driver (drivers/spi/spi_dw.c) computed the SPI BAUDR clock divider as info->clock_frequency / config->frequency without validating config->frequency. spi_transceive is a Zephyr __syscall and its verify handler (drivers/spi/spi_handlers.c) copies the…