VYPR

WinRAR

by WinRAR

CVEs (12)

  • CVE-2018-20250HigKEVFeb 5, 2019
    risk 0.79cvss 7.8epss 0.96

    In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating…

  • CVE-2025-8088HigKEVAug 8, 2025
    risk 0.76cvss 8.8epss 0.95

    A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček …

  • CVE-2014-125119HigJul 25, 2025
    risk 0.58cvss epss 0.01

    A filename spoofing vulnerability exists in WinRAR when opening specially crafted ZIP archives. The issue arises due to inconsistencies between the Central Directory and Local File Header entries in ZIP files. When viewed in WinRAR, the file name from the Central Directory is…

  • CVE-2018-20253HigFeb 13, 2019
    risk 0.51cvss 7.8epss 0.04

    In WinRAR versions prior to and including 5.60, There is an out-of-bounds write vulnerability during parsing of a crafted LHA / LZH archive formats. Successful exploitation could lead to arbitrary code execution in the context of the current user.

  • CVE-2018-20252HigFeb 5, 2019
    risk 0.51cvss 7.8epss 0.04

    In WinRAR versions prior to and including 5.60, there is an out-of-bounds write vulnerability during parsing of crafted ACE and RAR archive formats. Successful exploitation could lead to arbitrary code execution in the context of the current user.

  • CVE-2015-5663HigDec 30, 2015
    risk 0.48cvss 7.4epss 0.01

    The file-execution functionality in WinRAR before 5.30 beta 5 allows local users to gain privileges via a Trojan horse file with a name similar to an extensionless filename that was selected by the user.

  • CVE-2025-31334MedApr 3, 2025
    risk 0.44cvss 6.8epss 0.01

    Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file exists in WinRAR versions prior to 7.11. If a symbolic link specially crafted by an attacker is opened on the affected product, arbitrary…

  • CVE-2019-25677MedApr 5, 2026
    risk 0.40cvss 6.2epss 0.00

    WinRAR 5.61 contains a denial of service vulnerability that allows local attackers to crash the application by placing a malformed winrar.lng language file in the installation directory. Attackers can trigger the crash by opening an archive and pressing the test button, causing…

  • CVE-2018-20251MedFeb 5, 2019
    risk 0.38cvss 5.5epss 0.32

    In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field of the ACE format. The UNACE module (UNACEV2.dll) creates files and folders as written in the filename field even when WinRAR validator noticed the traversal…

  • CVE-2026-14191HigJul 1, 2026
    risk 0.00cvss 7.8epss 0.01

    An out-of-bounds heap write exists in the RAR5 recovery-volume (.rev) parser in WinRAR and UnRAR (RecVolumes5::ReadHeader in recvol5.cpp). The RecItems vector is sized only when the first .rev file in a set is processed; subsequent .rev files supply an independent RecNum value…

  • CVE-2005-4474Dec 22, 2005
    risk 0.00cvss epss 0.02

    Buffer overflow in the "Add to archive" command in WinRAR 3.51 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code by tricking the user into adding a file whose filename contains a non-default code page and non-ANSI characters,…

  • CVE-2005-0331May 2, 2005
    risk 0.00cvss epss 0.01

    Directory traversal vulnerability in WinRAR 3.42 and earlier, when the user clicks on the ZIP file to extract it, allows remote attackers to create arbitrary files via a ... (triple dot) in the filename of the ZIP file.