Skip to main content

Vendor/product archive

rarlab / unrar CVEs

Beta · best-effort

14 CVEs tagged to rarlab / unrar5 Critical, 6 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2022-48579

Published Aug 7, 2023

UnRAR before 6.2.3 allows extraction of files outside of the destination folder via symlink chains.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-20006

Published Jul 1, 2021

UnRAR 5.6.1.2 and 5.6.1.3 has a heap-based buffer overflow in Unpack::CopyString (called from Unpack::Unpack5 and CmdExtract::ExtractCurrentFile).

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14121

Published Sep 3, 2017

The DecodeNumber function in unrarlib.c in unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a NULL pointer dereference flaw triggered by a crafted RAR archive. NOTE: this ma…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14120

Published Sep 3, 2017

unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a directory traversal vulnerability for RAR v2 archives: pathnames of the form ../[filename] are unpacked into the upper dir…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12942

Published Aug 18, 2017

libunrar.a in UnRAR before 5.5.7 has a buffer overflow in the Unpack::LongLZ function.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-12941

Published Aug 18, 2017

libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the Unpack::Unpack20 function.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-12940

Published Aug 18, 2017

libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the EncodeFileName::Decode call within the Archive::ReadHeader15 function.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-12938

Published Aug 18, 2017

UnRAR before 5.5.7 allows remote attackers to bypass a directory-traversal protection mechanism via vectors involving a symlink to the . directory, a symlink to the .. directory,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-3726

Published Jul 12, 2007

Integer signedness error in the SET_VALUE function in rarvm.cpp in unrar 3.70 beta 3, as used in products including WinRAR and RAR for OS X, allows user-assisted remote attackers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0855

Published Feb 8, 2007

Stack-based buffer overflow in RARLabs Unrar, as packaged in WinRAR and possibly other products, allows user-assisted remote attackers to execute arbitrary code via a crafted, pas…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-14 of 14 CVEsPage 1 of 1