Rarlab Rar vulnerabilities
7 known vulnerabilities affecting rarlab/rar.
Total CVEs
7
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH3MEDIUM3LOW1
Vulnerabilities
Page 1 of 1
CVE-2025-14111LOWCVSS 2.3≤ 7.112025-12-05
CVE-2025-14111 [LOW] CWE-22 CVE-2025-14111: A security vulnerability has been detected in Rarlab RAR App up to 7.11 Build 127 on Android. This a
A security vulnerability has been detected in Rarlab RAR App up to 7.11 Build 127 on Android. This affects an unknown part of the component com.rarlab.rar. Such manipulation leads to path traversal. It is possible to launch the attack remotely. Attacks of this nature are highly complex. It is indicated that the exploitability is difficult. The exploit h
nvd
CVE-2022-30333HIGHCVSS 7.5KEVPoC≥ 0, < 2:6.23-1~20.04.1≥ 0, < 2:6.23-1~22.04.12025-03-12
CVE-2022-30333 [HIGH] rar vulnerabilities
rar vulnerabilities
It was discovered that RAR incorrectly handled certain paths. If a user or
automated system were tricked into extracting a specially crafted RAR
archive, a remote attacker could possibly use this issue to write arbitrary
files outside of the targeted directory. (CVE-2022-30333)
It was discovered that RAR incorrectly handled certain recovery volumes. If
a user or automated system were tricked into extracting a specially crafted
RAR a
osv
CVE-2023-40477HIGHCVSS 7.8≥ 0, < 2:6.23-1~deb11u1≥ 0, < 2:6.23-1~deb12u1+1 more2024-05-03
CVE-2023-40477 [HIGH] CVE-2023-40477: RARLAB WinRAR Recovery Volume Improper Validation of Array Index Remote Code Execution Vulnerability
RARLAB WinRAR Recovery Volume Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific f
osv
CVE-2024-33899HIGHCVSS 7.1≥ 0, < 2:7.01-1~deb12u1≥ 0, < 2:7.00-12024-04-29
CVE-2024-33899 [HIGH] CVE-2024-33899: RARLAB WinRAR before 7
RARLAB WinRAR before 7.00, on Linux and UNIX platforms, allows attackers to spoof the screen output, or cause a denial of service, via ANSI escape sequences.
osv
CVE-2014-9983MEDIUMCVSS 5.5v4.00v4.01+13 more2017-06-04
CVE-2014-9983 [MEDIUM] CWE-22 CVE-2014-9983: Directory Traversal exists in RAR 4.x and 5.x because an unpack operation follows any symlinks, incl
Directory Traversal exists in RAR 4.x and 5.x because an unpack operation follows any symlinks, including symlinks contained in the archive. This allows remote attackers to write to arbitrary files via a crafted archive.
nvdosv
CVE-2007-3726MEDIUMCVSS 4.3≥ 0, < 1:3.7b1-12007-07-12
CVE-2007-3726 [MEDIUM] CVE-2007-3726: Integer signedness error in the SET_VALUE function in rarvm
Integer signedness error in the SET_VALUE function in rarvm.cpp in unrar 3.70 beta 3, as used in products including WinRAR and RAR for OS X, allows user-assisted remote attackers to cause a denial of service (crash) via a crafted RAR archive that causes a negative signed number to be cast to a large unsigned number.
osv
CVE-2007-0855MEDIUMCVSS 6.8≥ 0, < 1:3.7b1-12007-02-08
CVE-2007-0855 [MEDIUM] CVE-2007-0855: Stack-based buffer overflow in RARLabs Unrar, as packaged in WinRAR and possibly other products, allows user-assisted remote attackers to execute arbi
Stack-based buffer overflow in RARLabs Unrar, as packaged in WinRAR and possibly other products, allows user-assisted remote attackers to execute arbitrary code via a crafted, password-protected archive.
osv