Vulnerability index

Browse CVEs

31 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Winrar MEDIUM 5.5
CVE-2019-25677

WinRAR 5.61 contains a denial of service vulnerability that allows local attackers to crash the application by placing a malformed winrar.lng languag…

Fix: after 5.61
Fix from $1,600 2026-04-05
Rar HIGH 8.1
CVE-2025-14111

A security vulnerability has been detected in Rarlab RAR App up to 7.11 Build 127 on Android. This affects an unknown part of the component com.rarla…

Fix: after 7.11
Fix from $1,950 2025-12-05
Winrar MEDIUM 6.1
CVE-2025-52331

Cross-site scripting (XSS) vulnerability in the generate report functionality in Rarlab WinRAR 7.11, allows attackers to disclose user information su…

Mitigation only
Fix from $1,600 2025-11-12
Winrar HIGH 8.8
CVE-2025-8088 KEVEPSS 95%

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive f…

Fix: 7.13 / 2023.01+
Fix from $1,950 2025-08-08
Winrar HIGH 7.8
CVE-2025-6218 KEVEPSS 89%

RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affect…

Fix: 7.12+
Fix from $1,950 2025-06-21
Winrar MEDIUM 6.8
CVE-2025-31334

Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file exists i…

Fix: 7.11+
Fix from $1,600 2025-04-03
Winrar HIGH 7.5
CVE-2024-36052

RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a different issue than CVE-2024-33899.

Fix: 7.00+
Fix from $1,950 2024-05-21
Winrar HIGH 7.8
CVE-2023-40477EPSS 12%

RARLAB WinRAR Recovery Volume Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows remote attackers to e…

Fix: 6.23+
Fix from $1,950 2024-05-03
Winrar HIGH 7.1
CVE-2024-33899

RARLAB WinRAR before 7.00, on Linux and UNIX platforms, allows attackers to spoof the screen output, or cause a denial of service, via ANSI escape se…

Fix: 7.00+
Fix from $1,950 2024-04-29
Winrar HIGH 7.8
CVE-2023-38831 KEVEPSS 98%

RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occur…

Fix: 6.23+
Fix from $1,950 2023-08-23
Unrar HIGH 7.5
CVE-2022-48579

UnRAR before 6.2.3 allows extraction of files outside of the destination folder via symlink chains.

Fix: 6.2.3+
Fix from $1,950 2023-08-07
Winrar HIGH 7.1
CVE-2022-43650EPSS 23%

This vulnerability allows remote attackers to disclose sensitive information on affected installations of RARLAB WinRAR 6.11.0.0. User interaction is…

Mitigation only
Fix from $1,950 2023-03-29
Unrar HIGH 7.8
CVE-2017-20006

UnRAR 5.6.1.2 and 5.6.1.3 has a heap-based buffer overflow in Unpack::CopyString (called from Unpack::Unpack5 and CmdExtract::ExtractCurrentFile).

Patch available
Fix from $1,950 2021-07-01
Unrar HIGH 7.8
CVE-2018-25018

UnRAR 5.6.1.7 through 5.7.4 and 6.0.3 has an out-of-bounds write during a memcpy in QuickOpen::ReadRaw when called from QuickOpen::ReadNext.

Fix: after 5.7.4
Fix from $1,950 2021-07-01
Winrar HIGH 7.8
CVE-2018-20253

In WinRAR versions prior to and including 5.60, There is an out-of-bounds write vulnerability during parsing of a crafted LHA / LZH archive formats. …

Fix: after 5.60
Fix from $1,950 2019-02-13
Winrar HIGH 7.8
CVE-2018-20250 KEVEPSS 96%

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.…

Fix: after 5.61
Fix from $1,950 2019-02-05
Winrar HIGH 7.8
CVE-2018-20252

In WinRAR versions prior to and including 5.60, there is an out-of-bounds write vulnerability during parsing of crafted ACE and RAR archive formats. …

Fix: after 5.60
Fix from $1,950 2019-02-05
Winrar MEDIUM 5.5
CVE-2018-20251EPSS 32%

In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field of the ACE format. The UNACE m…

Fix: after 5.61
Fix from $1,600 2019-02-05
Unrar CRITICAL 9.8
CVE-2017-12940

libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the EncodeFileName::Decode call within the Archive::ReadHeader15 function.

Fix: after 5.5.6
Fix from $2,300 2017-08-18
Unrar CRITICAL 9.8
CVE-2017-12941

libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the Unpack::Unpack20 function.

Fix: after 5.5.6
Fix from $2,300 2017-08-18
Unrar CRITICAL 9.8
CVE-2017-12942

libunrar.a in UnRAR before 5.5.7 has a buffer overflow in the Unpack::LongLZ function.

Fix: after 5.5.6
Fix from $2,300 2017-08-18
Unrar HIGH 7.5
CVE-2017-12938

UnRAR before 5.5.7 allows remote attackers to bypass a directory-traversal protection mechanism via vectors involving a symlink to the . directory, a…

Fix: after 5.5.6
Fix from $1,950 2017-08-18
Rar MEDIUM 5.5
CVE-2014-9983

Directory Traversal exists in RAR 4.x and 5.x because an unpack operation follows any symlinks, including symlinks contained in the archive. This all…

No fix yet
Fix from $1,600 2017-06-04
Winrar HIGH 7.4
CVE-2015-5663

The file-execution functionality in WinRAR before 5.30 beta 5 allows local users to gain privileges via a Trojan horse file with a name similar to an…

Fix: after 5.30
Fix from $1,950 2015-12-30
Winrar HIGH 10.0
CVE-2008-7144

Multiple unspecified vulnerabilities in RARLAB WinRAR before 3.71 have unknown impact and attack vectors related to crafted (1) ACE, (2) ARJ, (3) BZ2…

Fix: after 3.70
Fix from $1,950 2009-09-01
Unrar MEDIUM 6.8
CVE-2007-0855

Stack-based buffer overflow in RARLabs Unrar, as packaged in WinRAR and possibly other products, allows user-assisted remote attackers to execute arb…

Patch available
Fix from $1,600 2007-02-08
Winrar HIGH 9.3
CVE-2006-3845EPSS 8%

Stack-based buffer overflow in lzh.fmt in WinRAR 3.00 through 3.60 beta 6 allows remote attackers to execute arbitrary code via a long filename in a …

Patch available
Fix from $1,950 2006-07-25
Winrar MEDIUM 5.1
CVE-2005-4474

Buffer overflow in the "Add to archive" command in WinRAR 3.51 allows user-assisted attackers to cause a denial of service (crash) and possibly execu…

Mitigation only
Fix from $1,600 2005-12-22
Winrar HIGH 7.5
CVE-2005-3262EPSS 9%

Format string vulnerability in RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via format string specifiers in a UU…

Patch available
Fix from $1,950 2005-10-20
Winrar HIGH 7.5
CVE-2005-3263

Stack-based buffer overflow in UNACEV2.DLL for RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via an ACE archive c…

Patch available
Fix from $1,950 2005-10-20