Winrar
Rarlab · 28 CVEs
WinRAR / UnRAR RAR5 recovery-volume (.rev) out-of-bounds heap write in RecVolumes5::ReadHeader
Jul 1, 2026
WinRAR 5.61 Denial of Service via Malformed Language File
Apr 5, 2026
Cross-site scripting (XSS) vulnerability in the generate report functionality in Rarlab WinRAR 7.11, allows attackers t…
Nov 12, 2025
Path traversal vulnerability in WinRAR
Aug 8, 2025
WinRAR < 5.00 Filename Spoofing RCE
Jul 25, 2025
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability
Jun 21, 2025
Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points…
Apr 3, 2025
RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a differe…
May 21, 2024
RARLAB WinRAR Recovery Volume Improper Validation of Array Index Remote Code Execution Vulnerability
May 3, 2024
RARLAB WinRAR before 7.00, on Linux and UNIX platforms, allows attackers to spoof the screen output, or cause a denial…
Apr 28, 2024
RARLAB WinRAR Mark-Of-The-Web Bypass Vulnerability
Apr 2, 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within…
Aug 23, 2023
This vulnerability allows remote attackers to disclose sensitive information on affected installations of RARLAB WinRAR…
Mar 29, 2023
In WinRAR versions prior to and including 5.60, There is an out-of-bounds write vulnerability during parsing of a craft…
Feb 13, 2019
In WinRAR versions prior to and including 5.60, there is an out-of-bounds write vulnerability during parsing of crafted…
Feb 5, 2019
In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field…
Feb 5, 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field…
Feb 5, 2019
The file-execution functionality in WinRAR before 5.30 beta 5 allows local users to gain privileges via a Trojan horse…
Dec 30, 2015
Multiple unspecified vulnerabilities in RARLAB WinRAR before 3.71 have unknown impact and attack vectors related to cra…
Sep 1, 2009
Stack-based buffer overflow in the SFX module in WinRAR before 3.60 beta 8 has unspecified vectors and impact.
Jul 28, 2006
Stack-based buffer overflow in lzh.fmt in WinRAR 3.00 through 3.60 beta 6 allows remote attackers to execute arbitrary…
Jul 25, 2006
Buffer overflow in WinRAR 3.50 and earlier allows local users to execute arbitrary code via a long command-line argumen…
Jan 6, 2006
Buffer overflow in the "Add to archive" command in WinRAR 3.51 allows user-assisted attackers to cause a denial of serv…
Dec 22, 2005
Stack-based buffer overflow in UNACEV2.DLL for RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbit…
Oct 20, 2005
Format string vulnerability in RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via fo…
Oct 20, 2005
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-14191 | WinRAR / UnRAR RAR5 recovery-volume (.rev) out-of-bounds heap write in RecVolumes5::ReadHeader | HIGH | 0.44% | Jul 1, 2026 |
| CVE-2019-25677 | WinRAR 5.61 Denial of Service via Malformed Language File | MEDIUM | 0.43% | Apr 5, 2026 |
| CVE-2025-52331 | Cross-site scripting (XSS) vulnerability in the generate report functionality in Rarlab WinRAR 7.11, allows attackers to disclose user information such as the… | MEDIUM | 0.31% | Nov 12, 2025 |
| CVE-2025-8088 KEV | Path traversal vulnerability in WinRAR | HIGH | 94.05% | Aug 8, 2025 |
| CVE-2014-125119 | WinRAR < 5.00 Filename Spoofing RCE | HIGH | 1.71% | Jul 25, 2025 |
| CVE-2025-6218 KEV | RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability | HIGH | 90.48% | Jun 21, 2025 |
| CVE-2025-31334 | Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file exists in WinRAR v… | MEDIUM | 1.26% | Apr 3, 2025 |
| CVE-2024-36052 | RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a different issue than CVE-2024-33899. | HIGH | 0.75% | May 21, 2024 |
| CVE-2023-40477 | RARLAB WinRAR Recovery Volume Improper Validation of Array Index Remote Code Execution Vulnerability | HIGH | 11.38% | May 3, 2024 |
| CVE-2024-33899 | RARLAB WinRAR before 7.00, on Linux and UNIX platforms, allows attackers to spoof the screen output, or cause a denial of service, via ANSI escape sequences. | HIGH | 0.82% | Apr 28, 2024 |
| CVE-2024-30370 | RARLAB WinRAR Mark-Of-The-Web Bypass Vulnerability | MEDIUM | 1.15% | Apr 2, 2024 |
| CVE-2023-38831 KEV | RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because… | HIGH | 99.81% | Aug 23, 2023 |
| CVE-2022-43650 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of RARLAB WinRAR 6.11.0.0. User interaction is required… | HIGH | 23.04% | Mar 29, 2023 |
| CVE-2018-20253 | In WinRAR versions prior to and including 5.60, There is an out-of-bounds write vulnerability during parsing of a crafted LHA / LZH archive formats. Successful… | HIGH | 4.19% | Feb 13, 2019 |
| CVE-2018-20252 | In WinRAR versions prior to and including 5.60, there is an out-of-bounds write vulnerability during parsing of crafted ACE and RAR archive formats. Successful… | HIGH | 3.60% | Feb 5, 2019 |
| CVE-2018-20251 | In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field of the ACE format. The UNACE module (UNA… | MEDIUM | 31.40% | Feb 5, 2019 |
| CVE-2018-20250 KEV | In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When… | HIGH | 96.00% | Feb 5, 2019 |
| CVE-2015-5663 | The file-execution functionality in WinRAR before 5.30 beta 5 allows local users to gain privileges via a Trojan horse file with a name similar to an extension… | HIGH | 0.91% | Dec 30, 2015 |
| CVE-2008-7144 | Multiple unspecified vulnerabilities in RARLAB WinRAR before 3.71 have unknown impact and attack vectors related to crafted (1) ACE, (2) ARJ, (3) BZ2, (4) CAB,… | HIGH | 2.27% | Sep 1, 2009 |
| CVE-2006-3912 | Stack-based buffer overflow in the SFX module in WinRAR before 3.60 beta 8 has unspecified vectors and impact. | LOW | 5.67% | Jul 28, 2006 |
| CVE-2006-3845 | Stack-based buffer overflow in lzh.fmt in WinRAR 3.00 through 3.60 beta 6 allows remote attackers to execute arbitrary code via a long filename in a LHA archiv… | HIGH | 7.89% | Jul 25, 2006 |
| CVE-2005-4620 | Buffer overflow in WinRAR 3.50 and earlier allows local users to execute arbitrary code via a long command-line argument. NOTE: because this program executes w… | MEDIUM | 1.48% | Jan 6, 2006 |
| CVE-2005-4474 | Buffer overflow in the "Add to archive" command in WinRAR 3.51 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitra… | MEDIUM | 2.04% | Dec 22, 2005 |
| CVE-2005-3263 | Stack-based buffer overflow in UNACEV2.DLL for RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via an ACE archive containing… | HIGH | 3.69% | Oct 20, 2005 |
| CVE-2005-3262 | Format string vulnerability in RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via format string specifiers in a UUE/XXE file… | HIGH | 8.79% | Oct 20, 2005 |
Showing 1 to 25 of 28 CVEs