Vulnerabilities (CVE)

Filtered by vendor Rarlab Subscribe
Filtered by product Winrar
Total 26 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-0331 1 Rarlab 1 Winrar 2017-07-11 2.6 LOW N/A
Directory traversal vulnerability in WinRAR 3.42 and earlier, when the user clicks on the ZIP file to extract it, allows remote attackers to create arbitrary files via a ... (triple dot) in the filename of the ZIP file.
CVE-2004-1495 1 Rarlab 1 Winrar 2017-07-11 2.6 LOW N/A
The Repair Archive command in WinRAR 3.40 allows remote attackers to cause a denial of service (application crash) via a corrupt ZIP archive.
CVE-2004-1254 1 Rarlab 1 Winrar 2017-07-11 10.0 HIGH N/A
WinRAR 3.40, and possibly earlier versions, allows remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename, possibly causing an integer overflow that leads to a buffer overflow.
CVE-2015-5663 1 Rarlab 1 Winrar 2016-12-06 3.7 LOW 7.4 HIGH
The file-execution functionality in WinRAR before 5.30 beta 5 allows local users to gain privileges via a Trojan horse file with a name similar to an extensionless filename that was selected by the user.
CVE-2005-3263 1 Rarlab 1 Winrar 2008-09-10 7.5 HIGH N/A
Stack-based buffer overflow in UNACEV2.DLL for RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via an ACE archive containing a file with a long name.
CVE-2005-3262 1 Rarlab 1 Winrar 2008-09-10 7.5 HIGH N/A
Format string vulnerability in RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via format string specifiers in a UUE/XXE file, which are not properly handled when WinRAR displays diagnostic errors related to an invalid filename.