Threats Tagged 'cwe-369'
View all threats tagged with 'cwe-369'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-369'
Click on any threat for detailed analysis and mitigation recommendations
In the silabser.sys Windows 8 driver for CP210x devices, a local unprivileged user can use incorrect driver settings to cause a kernel crash. Join the discussion | CVE Database V5 | 09/10/2026, 17:13:56 UTC Added: 09/10/2026, 17:37:58 UTC |
libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero. In particular uncommon use cases a crafted filter program can cause a division by zero. Join the discussion | CVE Database V5 | 09/05/2026, 18:50:39 UTC Added: 09/05/2026, 19:07:54 UTC |
Bulletin ID: 2026-015-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/07 15:30 PM PDT Description: Firecracker is an open source virtualization technology that is purpose-built for creating and managing secure, multi-tenant container and function-based services. We identified CVE-2026-5747, an out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and aarch64 that might allow a local guest user with root privileges to crash the Firecracker VMM process or potentially execute arbitrary code on the host via modification of virtio queue configuration registers after device activation. Achieving code execution on the host requires additional preconditions, such as the use of a custom guest kernel or specific snapshot configurations. No AWS service is affected. Impacted versions: Firecracker >= 1.13.0 AND <= 1.14.3 AND 1.15.0 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin. Join the discussion | CVE Database V5 | 08/20/2026, 21:35:57 UTC Added: 04/07/2026, 23:31:34 UTC |
0 CVE-2026-16897 is a medium severity vulnerability in IBM AIX versions 7.2 and 7.3, and IBM PowerVM VIOS 4.1. It involves a divide-by-zero condition (CWE-369) that can be triggered by a local attacker, potentially causing a denial of service via an out-of-bounds write. Join the discussion | CVE Database V5 | 08/19/2026, 19:54:33 UTC Added: 08/19/2026, 20:07:52 UTC |
A rogue Velociraptor client can upload a malformed sparse file such that if the GUI attempts to expand the file, a panic occurs which may crash the server process. The problem is a Divide by Zero bug in the ShouldPadFile() function. Join the discussion | CVE Database V5 | 08/12/2026, 09:49:25 UTC Added: 08/12/2026, 10:11:55 UTC |
Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by maliciously crafted NTFS images. Typically Velociraptor's NTFS parser is used on live NTFS filesystems, limiting the opportunity of attackers corrupting the filesystem. However, in some applications (e.g. dead disk forensics https://docs.velociraptor.app/docs/forensic/deaddisk/ ) Velociraptor may be used on untrusted NTFS image files. If an attacker is able to inject maliciously corrupted NTFS Volumes they can cause a crash and a Denial of Service. Join the discussion | CVE Database V5 | 08/11/2026, 14:47:13 UTC Added: 08/11/2026, 14:57:23 UTC |
0 Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able to run as a different user, the calling user needs to have the IMPERSONATE permission (usually only given to administrators). Velociraptor versions prior to 0.77.2 evaluate this permission against the caller's org instead of against the target org. This allows an administrator in one org to impersonate another user in another org, in which they may not have the IMPERSONATE permission. Join the discussion | CVE Database V5 | 08/11/2026, 14:15:58 UTC Added: 08/11/2026, 14:41:51 UTC |
0 A divide-by-zero vulnerability exists in HDF5 through version 2.3.0 due to improper validation of chunk-layout dimensionality against dataspace rank when opening an existing dataset. This can cause a denial of service via application crash when processing a crafted HDF5 file. Join the discussion | CVE Database V5 | 08/05/2026, 22:35:11 UTC Added: 08/05/2026, 22:56:45 UTC |
CVE-2026-61378 is a divide-by-zero vulnerability in AutomationDirect's Productivity Suite. This flaw allows a local attacker to cause a division by zero, resulting in a system crash. The vulnerability does not impact confidentiality or integrity but causes a denial of service. No patch or official remediation has been confirmed yet. The vulnerability has a medium severity rating with a CVSS score of 5.5. Join the discussion | CVE Database V5 | 07/16/2026, 20:30:30 UTC Added: 07/16/2026, 20:48:20 UTC |
0 FatFs R0.16 and earlier contains a divide-by-zero in exFAT sync logic bug when crafted metadata causes n_fatent - 2 to be zero during write/sync operations. This maps to CWE-369 (Divide By Zero). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (4.6, Medium). Network-delivered update media can make this remote in some pipelines. The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Partial. Join the discussion | CVE Database V5 | 07/01/2026, 13:41:11 UTC Added: 07/01/2026, 14:37:00 UTC |
Showing 1 to 10 of 33 results