CVE-2023-0512
📛 CVE Title
Divide By Zero in vim/vim
Description
Divide By Zero in GitHub repository vim/vim prior to 9.0.1247.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- @huntrdev
- CVSS severity
- HIGH
- CVSS score
- 7.3 / 10
- CVSS vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H- Effective score
- 7.3 / 10 HIGH source: CNA overview
- MSRC score
- 7.8 / 10 HIGH MS rating: Important
- CWE(s)
-
CWE-369 - Reserved
- 2023-01-26
- Published
- 2023-01-26 01:00 UTC
- Last updated
- 2025-03-31 18:44 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/0xxx/CVE-2023-0512.json
- Linked Threat
- CVE-2023-0512 — Divide By Zero in vim/vim
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2023-12558 - Assigner
- @huntrdev
- Published
- Jan 26, 2023, 12:00:00 AM
- Updated
- Mar 31, 2025, 4:44:58 PM
- EUVD base score (CVSS 3.0)
-
7.3 / 10
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H - EUVD-reported EPSS
- 0.0400
- Vendors
- vim
- Products
-
vim/vim (unspecified <9.0.1247)
- Aliases
-
GHSA-whp8-xgvp-xj3v
ENISA description: Divide By Zero in GitHub repository vim/vim prior to 9.0.1247.
EUVD references (9)
- https://huntr.dev/bounties/de83736a-1936-4872-830b-f1e9b0ad2a74
- https://github.com/vim/vim/commit/870219c58c0804bdc55419b2e455c06ac715a835
- https://support.apple.com/kb/HT213677
- https://support.apple.com/kb/HT213675
- https://support.apple.com/kb/HT213670
- http://seclists.org/fulldisclosure/2023/Mar/17
- http://seclists.org/fulldisclosure/2023/Mar/18
- http://seclists.org/fulldisclosure/2023/Mar/21
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IE44W6WMMREYCW3GJHPSYP7NK2VT5NY6/
Microsoft Security Response Center MSRC
Microsoft's vendor-authoritative record from the Security Update Guide — its own CVSS score, impact, severity rating, exploit assessment, and KB-article fixes. Refreshed 2026-08-12 01:00 UTC (source: CVRF).
- MS severity
- Important
- MS CVSS base score
- 7.8 / 10 (temporal 7.8)
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - Release
- 2023-Jan
Microsoft remediations / KB articles (2)
- CBL-Mariner Releases — Vendor Fix / Security Update (fixed build 9.0.1247-1)
- https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade — None Available / CBL-Mariner Releases
Microsoft FAQ (1)
Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| vim | vim/vim |
unspecified (affected)
|
— |
Vendor references (9)
References embedded in the original CVE record by the assigning CNA.
- https://huntr.dev/bounties/de83736a-1936-4872-830b-f1e9b0ad2a74
- https://github.com/vim/vim/commit/870219c58c0804bdc55419b2e455c06ac715a835
- https://support.apple.com/kb/HT213677
- https://support.apple.com/kb/HT213675
- https://support.apple.com/kb/HT213670
- 20230327 APPLE-SA-2023-03-27-3 macOS Ventura 13.3 mailing-list
- 20230327 APPLE-SA-2023-03-27-4 macOS Monterey 12.6.4 mailing-list
- 20230327 APPLE-SA-2023-03-27-5 macOS Big Sur 11.7.5 mailing-list
- FEDORA-2023-030318ca00 vendor-advisory
Web references (13)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- None Available msrc
- MSRC update guide: CVE-2023-0512 msrc
- https://support.apple.com/kb/HT213843 rapid7:support.apple.com
- https://support.apple.com/kb/HT213670 rapid7:support.apple.com
- https://support.apple.com/kb/HT213677 rapid7:support.apple.com
- https://support.apple.com/kb/HT213675 rapid7:support.apple.com
- https://security.alpinelinux.org/vuln/CVE-2023-0512 rapid7:security.alpinelinux.org
- https://alas.aws.amazon.com/AL2023/ALAS-2023-117.html rapid7:alas.aws.amazon.com
- https://www.dell.com/support/kbdoc/en-us/000218046/dsa-2023-366-dell-powerstore-family-security-update-for-multiple-vulnerabilities rapid7:www.dell.com
- https://attackerkb.com/topics/CVE-2023-0512 rapid7:attackerkb.com
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-12558 rapid7:euvd.enisa.europa.eu
- https://www.cve.org/CVERecord?id=CVE-2023-0512 rapid7:www.cve.org
- http://cwe.mitre.org/data/definitions/369.html rapid7:cwe.mitre.org
Remediations (13)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:support.servicenow.com
Overview The advisories below document publicly disclosed Common Vulnerabilities and Exposures ( CVEs ) in the Now Platform by ServiceNow. Because ServiceNow uses various methods to communicate vulnerability information, patches, and other fixes, customers should review family, security patch , and hotfix release notes, which are available at https://docs.servicenow.com, for a complete list of ...
2026-06-02 00:49 UTC -
web:attack.mitre.org
This mitigation can be implemented through the following measures: Regular Operating System Updates Implementation: Apply the latest Windows security updates monthly using WSUS (Windows Server Update Services) or a similar patch management solution. Configure systems to check for updates automatically and schedule reboots during maintenance ...
2026-06-02 00:49 UTC -
web:cybersecuritynews.com
Microsoft has rolled out a new cumulative update, KB5089573, for Windows 11 versions 25H2 and 24H2, targeting a critical installation failure that affected users following the May 2026 Patch Tuesday release.
2026-06-02 00:49 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-22 05:35 UTC -
web:support.servicenow.com
This document lists all the released Store applications and schema changes for Vulnerability Response and Configuration Compliance. Vulnerability Response and Configuration Compliance Compatibility Matrix
2026-05-22 05:35 UTC -
web:translate.google.com
Google's service, offered free of charge, instantly translates words, phrases, and web pages between English and over 100 other languages.
2026-05-22 05:35 UTC -
web:www.cve.org
At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures
2026-05-22 05:35 UTC -
web:www.cybersecuritydive.com
The Cybersecurity and Infrastructure Security Agency added two major software flaws to its Known Exploited Vulnerabilities (KEV) catalog on Tuesday, acknowledging the evidence that hackers have been using the bugs in recent attacks. CISA added CVE -2024-1708, a high-severity flaw in ConnectWise's ScreenConnect remote-access tool, and CVE -2026-32202, a medium-severity flaw in the Windows Shell ...
2026-05-22 05:35 UTC -
web:www.virustotal.com
VirusTotal is a platform for scanning files and URLs for viruses, malware, and other threats using multiple antivirus engines.
2026-05-22 05:35 UTC -
web:access.redhat.com
Learn about our open source products, services, and company. You are here
2026-05-22 05:35 UTC -
web:zecurit.com
Get the complete breakdown of Microsoft's May 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .
2026-05-22 05:35 UTC -
web:federalnewsnetwork.com
CISA this year has already started accelerating the deadlines for agencies to patch software bugs posted to the Known Exploited Vulnerabilities (KEV) catalog.
2026-05-22 05:35 UTC -
web:nvd.nist.gov
The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics. For ...
2026-05-22 05:35 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2023-0512.json.
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T05:17:49.385Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://huntr.dev/bounties/de83736a-1936-4872-830b-f1e9b0ad2a74"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/vim/vim/commit/870219c58c0804bdc55419b2e455c06ac715a835"
},
{
"tags": [
"x_transferred"
],
"url": "https://support.apple.com/kb/HT213677"
},
{
"tags": [
"x_transferred"
],
"url": "https://support.apple.com/kb/HT213675"
},
{
"tags": [
"x_transferred"
],
"url": "https://support.apple.com/kb/HT213670"
},
{
"name": "20230327 APPLE-SA-2023-03-27-3 macOS Ventura 13.3",
"tags": [
"mailing-list",
"x_transferred"
],
"url": "http://seclists.org/fulldisclosure/2023/Mar/17"
},
{
"name": "20230327 APPLE-SA-2023-03-27-4 macOS Monterey 12.6.4",
"tags": [
"mailing-list",
"x_transferred"
],
"url": "http://seclists.org/fulldisclosure/2023/Mar/18"
},
{
"name": "20230327 APPLE-SA-2023-03-27-5 macOS Big Sur 11.7.5",
"tags": [
"mailing-list",
"x_transferred"
],
"url": "http://seclists.org/fulldisclosure/2023/Mar/21"
},
{
"name": "FEDORA-2023-030318ca00",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IE44W6WMMREYCW3GJHPSYP7NK2VT5NY6/"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2023-0512",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-03-31T16:44:49.926506Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-03-31T16:44:58.673Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "vim/vim",
"vendor": "vim",
"versions": [
{
"lessThan": "9.0.1247",
"status": "affected",
"version": "unspecified",
"versionType": "custom"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Divide By Zero in GitHub repository vim/vim prior to 9.0.1247."
}
],
"metrics": [
{
"cvssV3_0": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.3,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
"version": "3.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-369",
"description": "CWE-369 Divide By Zero",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2023-04-02T00:00:00.000Z",
"orgId": "c09c270a-b464-47c1-9133-acb35b22c19a",
"shortName": "@huntrdev"
},
"references": [
{
"url": "https://huntr.dev/bounties/de83736a-1936-4872-830b-f1e9b0ad2a74"
},
{
"url": "https://github.com/vim/vim/commit/870219c58c0804bdc55419b2e455c06ac715a835"
},
{
"url": "https://support.apple.com/kb/HT213677"
},
{
"url": "https://support.apple.com/kb/HT213675"
},
{
"url": "https://support.apple.com/kb/HT213670"
},
{
"name": "20230327 APPLE-SA-2023-03-27-3 macOS Ventura 13.3",
"tags": [
"mailing-list"
],
"url": "http://seclists.org/fulldisclosure/2023/Mar/17"
},
{
"name": "20230327 APPLE-SA-2023-03-27-4 macOS Monterey 12.6.4",
"tags": [
"mailing-list"
],
"url": "http://seclists.org/fulldisclosure/2023/Mar/18"
},
{
"name": "20230327 APPLE-SA-2023-03-27-5 macOS Big Sur 11.7.5",
"tags": [
"mailing-list"
],
"url": "http://seclists.org/fulldisclosure/2023/Mar/21"
},
{
"name": "FEDORA-2023-030318ca00",
"tags": [
"vendor-advisory"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IE44W6WMMREYCW3GJHPSYP7NK2VT5NY6/"
}
],
"source": {
"advisory": "de83736a-1936-4872-830b-f1e9b0ad2a74",
"discovery": "EXTERNAL"
},
"title": "Divide By Zero in vim/vim"
}
},
"cveMetadata": {
"assignerOrgId": "c09c270a-b464-47c1-9133-acb35b22c19a",
"assignerShortName": "@huntrdev",
"cveId": "CVE-2023-0512",
"datePublished": "2023-01-26T00:00:00.000Z",
"dateReserved": "2023-01-26T00:00:00.000Z",
"dateUpdated": "2025-03-31T16:44:58.673Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}