{"id":"CVE-2025-4637","summary":"Divide By Zero in dlib","details":"Divide By Zero vulnerability in davisking dlib allows \n\nremote attackers to cause a denial of service via a crafted file.\n\n.This issue affects dlib: before \u003c19.24.7.","modified":"2026-08-12T15:16:32.380514Z","published":"2025-05-14T17:51:41.076Z","database_specific":{"cna_assigner":"GovTech CSG","cwe_ids":["CWE-369"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/4xxx/CVE-2025-4637.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/4xxx/CVE-2025-4637.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-4637"},{"type":"FIX","url":"https://github.com/davisking/dlib/pull/3058"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/davisking/dlib","events":[{"introduced":"0"},{"fixed":"d3520131a6e0e0fb62bc556b0222b45d99caf905"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0"},{"fixed":"\u003c19.24.7"}]}}],"versions":["v19.24.6","v19.24.5","v19.24.4","v19.24.3","v19.24.2","v19.24","v19.23","v19.22","v19.21","v19.20","v19.19","v19.18","v19.17","v19.16","v19.15","v19.14","v19.13","v19.12","v19.11","v19.10","v19.9","v19.8","v19.7","v19.6","v19.5","v19.4","v19.3","v19.2","v19.1","v19.0","before_dnn_serialization_cleanup","v18.17","v18.16","v18.15","v18.14","v18.13","v18.11","v18.10","v18.9","v18.8","v18.7","v18.6","v18.5","v18.3","v18.2","v18.1","v18.0","v17.49","v17.48","v17.47","v17.46","v17.45","v17.44","v17.43","v17.42","v17.41","v17.40","v17.39"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-4637.json","vanir_signatures_modified":"2026-08-12T15:16:32Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["251525035850748163704884515424787085222","211824620735229762740307118992195541003","293271418580817699955126967276983120847","26620686283558538696934275935257694397"],"threshold":0.9},"id":"CVE-2025-4637-16fab9d9","signature_type":"Line","signature_version":"v1","source":"https://github.com/davisking/dlib/commit/d3520131a6e0e0fb62bc556b0222b45d99caf905","target":{"file":"dlib/serialize.h"}},{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["186570859467469337541474623080110288327","315490352290462712377902813751347476351","88663287399133854283129400369494530089","300811556964532200184459073794639651275"]},"id":"CVE-2025-4637-8bb04856","signature_type":"Line","signature_version":"v1","source":"https://github.com/davisking/dlib/commit/d3520131a6e0e0fb62bc556b0222b45d99caf905","target":{"file":"dlib/unicode/unicode.h"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/S:N/AU:Y/R:U/V:D/RE:M/U:Amber"}]}