Show filters
37 Total Results
Displaying 21-30 of 37
Sort by:
Attacker Value
Unknown

CVE-2014-9983

Disclosure Date: June 04, 2017 (last updated November 26, 2024)
Directory Traversal exists in RAR 4.x and 5.x because an unpack operation follows any symlinks, including symlinks contained in the archive. This allows remote attackers to write to arbitrary files via a crafted archive.
0
Attacker Value
Unknown

CVE-2015-5663

Disclosure Date: December 30, 2015 (last updated November 25, 2024)
The file-execution functionality in WinRAR before 5.30 beta 5 allows local users to gain privileges via a Trojan horse file with a name similar to an extensionless filename that was selected by the user.
0
Attacker Value
Unknown

CVE-2008-7144

Disclosure Date: September 01, 2009 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in RARLAB WinRAR before 3.71 have unknown impact and attack vectors related to crafted (1) ACE, (2) ARJ, (3) BZ2, (4) CAB, (5) GZ, (6) LHA, (7) RAR, (8) TAR, or (9) ZIP files, as demonstrated by the OUSPG PROTOS GENOME test suite for Archive Formats.
0
Attacker Value
Unknown

CVE-2007-3726

Disclosure Date: July 12, 2007 (last updated October 04, 2023)
Integer signedness error in the SET_VALUE function in rarvm.cpp in unrar 3.70 beta 3, as used in products including WinRAR and RAR for OS X, allows user-assisted remote attackers to cause a denial of service (crash) via a crafted RAR archive that causes a negative signed number to be cast to a large unsigned number.
0
Attacker Value
Unknown

CVE-2007-0855

Disclosure Date: February 08, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in RARLabs Unrar, as packaged in WinRAR and possibly other products, allows user-assisted remote attackers to execute arbitrary code via a crafted, password-protected archive.
0
Attacker Value
Unknown

CVE-2006-3912

Disclosure Date: July 28, 2006 (last updated October 04, 2023)
Stack-based buffer overflow in the SFX module in WinRAR before 3.60 beta 8 has unspecified vectors and impact.
0
Attacker Value
Unknown

CVE-2006-3845

Disclosure Date: July 25, 2006 (last updated October 04, 2023)
Stack-based buffer overflow in lzh.fmt in WinRAR 3.00 through 3.60 beta 6 allows remote attackers to execute arbitrary code via a long filename in a LHA archive.
0
Attacker Value
Unknown

CVE-2005-4620

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Buffer overflow in WinRAR 3.50 and earlier allows local users to execute arbitrary code via a long command-line argument. NOTE: because this program executes with the privileges of the invoking user, and because remote programs do not normally have the ability to specify a command-line argument for this program, there may not be a typical attack vector for the issue that crosses privilege boundaries. Therefore this may not be a vulnerability.
0
Attacker Value
Unknown

CVE-2005-4474

Disclosure Date: December 22, 2005 (last updated February 22, 2025)
Buffer overflow in the "Add to archive" command in WinRAR 3.51 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code by tricking the user into adding a file whose filename contains a non-default code page and non-ANSI characters, as demonstrated using a Chinese filename, possibly due to buffer expansion when using the WideCharToMultiByte API. NOTE: it is not clear whether this problem can be exploited for code execution. If not, then perhaps the user-assisted nature of the attack should exclude the issue from inclusion in CVE.
0
Attacker Value
Unknown

CVE-2005-3263

Disclosure Date: October 20, 2005 (last updated February 22, 2025)
Stack-based buffer overflow in UNACEV2.DLL for RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via an ACE archive containing a file with a long name.
0