Rarlab Rar vulnerabilities

7 known vulnerabilities affecting rarlab/rar.

Total CVEs
7
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH3MEDIUM3LOW1

Vulnerabilities

Page 1 of 1
CVE-2025-14111LOWCVSS 2.3≤ 7.112025-12-05
CVE-2025-14111 [LOW] CWE-22 CVE-2025-14111: A security vulnerability has been detected in Rarlab RAR App up to 7.11 Build 127 on Android. This a A security vulnerability has been detected in Rarlab RAR App up to 7.11 Build 127 on Android. This affects an unknown part of the component com.rarlab.rar. Such manipulation leads to path traversal. It is possible to launch the attack remotely. Attacks of this nature are highly complex. It is indicated that the exploitability is difficult. The exploit h
nvd
CVE-2022-30333HIGHCVSS 7.5KEVPoC≥ 0, < 2:6.23-1~20.04.1≥ 0, < 2:6.23-1~22.04.12025-03-12
CVE-2022-30333 [HIGH] rar vulnerabilities rar vulnerabilities It was discovered that RAR incorrectly handled certain paths. If a user or automated system were tricked into extracting a specially crafted RAR archive, a remote attacker could possibly use this issue to write arbitrary files outside of the targeted directory. (CVE-2022-30333) It was discovered that RAR incorrectly handled certain recovery volumes. If a user or automated system were tricked into extracting a specially crafted RAR a
osv
CVE-2023-40477HIGHCVSS 7.8≥ 0, < 2:6.23-1~deb11u1≥ 0, < 2:6.23-1~deb12u1+1 more2024-05-03
CVE-2023-40477 [HIGH] CVE-2023-40477: RARLAB WinRAR Recovery Volume Improper Validation of Array Index Remote Code Execution Vulnerability RARLAB WinRAR Recovery Volume Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific f
osv
CVE-2024-33899HIGHCVSS 7.1≥ 0, < 2:7.01-1~deb12u1≥ 0, < 2:7.00-12024-04-29
CVE-2024-33899 [HIGH] CVE-2024-33899: RARLAB WinRAR before 7 RARLAB WinRAR before 7.00, on Linux and UNIX platforms, allows attackers to spoof the screen output, or cause a denial of service, via ANSI escape sequences.
osv
CVE-2014-9983MEDIUMCVSS 5.5v4.00v4.01+13 more2017-06-04
CVE-2014-9983 [MEDIUM] CWE-22 CVE-2014-9983: Directory Traversal exists in RAR 4.x and 5.x because an unpack operation follows any symlinks, incl Directory Traversal exists in RAR 4.x and 5.x because an unpack operation follows any symlinks, including symlinks contained in the archive. This allows remote attackers to write to arbitrary files via a crafted archive.
nvdosv
CVE-2007-3726MEDIUMCVSS 4.3≥ 0, < 1:3.7b1-12007-07-12
CVE-2007-3726 [MEDIUM] CVE-2007-3726: Integer signedness error in the SET_VALUE function in rarvm Integer signedness error in the SET_VALUE function in rarvm.cpp in unrar 3.70 beta 3, as used in products including WinRAR and RAR for OS X, allows user-assisted remote attackers to cause a denial of service (crash) via a crafted RAR archive that causes a negative signed number to be cast to a large unsigned number.
osv
CVE-2007-0855MEDIUMCVSS 6.8≥ 0, < 1:3.7b1-12007-02-08
CVE-2007-0855 [MEDIUM] CVE-2007-0855: Stack-based buffer overflow in RARLabs Unrar, as packaged in WinRAR and possibly other products, allows user-assisted remote attackers to execute arbi Stack-based buffer overflow in RARLabs Unrar, as packaged in WinRAR and possibly other products, allows user-assisted remote attackers to execute arbitrary code via a crafted, password-protected archive.
osv