Winrar

Rarlab · 28 CVEs

CVE-2026-14191
HIGH

WinRAR / UnRAR RAR5 recovery-volume (.rev) out-of-bounds heap write in RecVolumes5::ReadHeader

Jul 1, 2026

CVE-2019-25677
MEDIUM

WinRAR 5.61 Denial of Service via Malformed Language File

Apr 5, 2026

CVE-2025-52331
MEDIUM

Cross-site scripting (XSS) vulnerability in the generate report functionality in Rarlab WinRAR 7.11, allows attackers t…

Nov 12, 2025

CVE-2025-8088
KEV HIGH

Path traversal vulnerability in WinRAR

Aug 8, 2025

CVE-2014-125119
HIGH

WinRAR < 5.00 Filename Spoofing RCE

Jul 25, 2025

CVE-2025-6218
KEV HIGH

RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability

Jun 21, 2025

CVE-2025-31334
MEDIUM

Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points…

Apr 3, 2025

CVE-2024-36052
HIGH

RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a differe…

May 21, 2024

CVE-2023-40477
HIGH

RARLAB WinRAR Recovery Volume Improper Validation of Array Index Remote Code Execution Vulnerability

May 3, 2024

CVE-2024-33899
HIGH

RARLAB WinRAR before 7.00, on Linux and UNIX platforms, allows attackers to spoof the screen output, or cause a denial…

Apr 28, 2024

CVE-2024-30370
MEDIUM

RARLAB WinRAR Mark-Of-The-Web Bypass Vulnerability

Apr 2, 2024

CVE-2023-38831
KEV HIGH

RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within…

Aug 23, 2023

CVE-2022-43650
HIGH

This vulnerability allows remote attackers to disclose sensitive information on affected installations of RARLAB WinRAR…

Mar 29, 2023

CVE-2018-20253
HIGH

In WinRAR versions prior to and including 5.60, There is an out-of-bounds write vulnerability during parsing of a craft…

Feb 13, 2019

CVE-2018-20252
HIGH

In WinRAR versions prior to and including 5.60, there is an out-of-bounds write vulnerability during parsing of crafted…

Feb 5, 2019

CVE-2018-20251
MEDIUM

In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field…

Feb 5, 2019

CVE-2018-20250
KEV HIGH

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field…

Feb 5, 2019

CVE-2015-5663
HIGH

The file-execution functionality in WinRAR before 5.30 beta 5 allows local users to gain privileges via a Trojan horse…

Dec 30, 2015

CVE-2008-7144
HIGH

Multiple unspecified vulnerabilities in RARLAB WinRAR before 3.71 have unknown impact and attack vectors related to cra…

Sep 1, 2009

CVE-2006-3912
LOW

Stack-based buffer overflow in the SFX module in WinRAR before 3.60 beta 8 has unspecified vectors and impact.

Jul 28, 2006

CVE-2006-3845
HIGH

Stack-based buffer overflow in lzh.fmt in WinRAR 3.00 through 3.60 beta 6 allows remote attackers to execute arbitrary…

Jul 25, 2006

CVE-2005-4620
MEDIUM

Buffer overflow in WinRAR 3.50 and earlier allows local users to execute arbitrary code via a long command-line argumen…

Jan 6, 2006

CVE-2005-4474
MEDIUM

Buffer overflow in the "Add to archive" command in WinRAR 3.51 allows user-assisted attackers to cause a denial of serv…

Dec 22, 2005

CVE-2005-3263
HIGH

Stack-based buffer overflow in UNACEV2.DLL for RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbit…

Oct 20, 2005

CVE-2005-3262
HIGH

Format string vulnerability in RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via fo…

Oct 20, 2005

Showing 1 to 25 of 28 CVEs