Skip to main content

Vendor archive

rarlab CVEs

Beta · best-effort

45 CVEs tagged to vendor rarlab9 Critical, 19 High, 13 Medium, 4 Low, 0 Unrated.

CVE-2019-25677

Published Apr 5, 2026

WinRAR 5.61 contains a denial of service vulnerability that allows local attackers to crash the application by placing a malformed winrar.lng language file in the installation dir…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-14111

Published Dec 5, 2025

A security vulnerability has been detected in Rarlab RAR App up to 7.11 Build 127 on Android. This affects an unknown part of the component com.rarlab.rar. Such manipulation leads…

CVSS 1.3 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-52331

Published Nov 12, 2025

Cross-site scripting (XSS) vulnerability in the generate report functionality in Rarlab WinRAR 7.11, allows attackers to disclose user information such as the computer username, g…

CVSS 6.1 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2025-8088

Published Aug 8, 2025

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was e…

CVSS 8.4 · High
evidence mentions
36
Buzz score
75.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2025-6218

Published Jun 21, 2025

RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB Win…

CVSS 7.8 · High
evidence mentions
10
Buzz score
69.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2025-31334

Published Apr 3, 2025

Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file exists in WinRAR versions prior to 7.1…

CVSS 6.8 · Medium
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2024-36052

Published May 21, 2024

RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a different issue than CVE-2024-33899.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40477

Published May 3, 2024

RARLAB WinRAR Recovery Volume Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affec…

CVSS 7.8 · High
evidence mentions
11
Buzz score
40.9
Vendor/product tagsBeta · best-effort

CVE-2024-30370

Published Apr 2, 2024

RARLAB WinRAR Mark-Of-The-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-Of-The-Web protection mechanism on affected installations of RARL…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38831

Published Aug 23, 2023

RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may in…

CVSS 7.8 · High
evidence mentions
30
Buzz score
81.5
KEV listedPublic PoC observed
Vendor/product tagsBeta · best-effort

CVE-2022-48579

Published Aug 7, 2023

UnRAR before 6.2.3 allows extraction of files outside of the destination folder via symlink chains.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-43650

Published Mar 29, 2023

This vulnerability allows remote attackers to disclose sensitive information on affected installations of RARLAB WinRAR 6.11.0.0. User interaction is required to exploit this vuln…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-20006

Published Jul 1, 2021

UnRAR 5.6.1.2 and 5.6.1.3 has a heap-based buffer overflow in Unpack::CopyString (called from Unpack::Unpack5 and CmdExtract::ExtractCurrentFile).

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20253

Published Feb 13, 2019

In WinRAR versions prior to and including 5.60, There is an out-of-bounds write vulnerability during parsing of a crafted LHA / LZH archive formats. Successful exploitation could…

CVSS 7.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2018-20252

Published Feb 5, 2019

In WinRAR versions prior to and including 5.60, there is an out-of-bounds write vulnerability during parsing of crafted ACE and RAR archive formats. Successful exploitation could…

CVSS 7.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2018-20251

Published Feb 5, 2019

In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field of the ACE format. The UNACE module (UNACEV2.dll) creates fi…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2018-20250

Published Feb 5, 2019

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field…

CVSS 7.8 · High
evidence mentions
31
Buzz score
79.5
KEV listedPublic PoC observed
Vendor/product tagsBeta · best-effort

CVE-2017-14121

Published Sep 3, 2017

The DecodeNumber function in unrarlib.c in unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a NULL pointer dereference flaw triggered by a crafted RAR archive. NOTE: this ma…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14120

Published Sep 3, 2017

unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a directory traversal vulnerability for RAR v2 archives: pathnames of the form ../[filename] are unpacked into the upper dir…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12942

Published Aug 18, 2017

libunrar.a in UnRAR before 5.5.7 has a buffer overflow in the Unpack::LongLZ function.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-12941

Published Aug 18, 2017

libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the Unpack::Unpack20 function.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 45 CVEsPage 1 of 2