Rarzilla Unrar-Free vulnerabilities

5 known vulnerabilities affecting rarzilla/unrar-free.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2017-14122CRITICALCVSS 9.1≥ 0, < 1:0.0.1+cvs20140707-42017-09-03
CVE-2017-14122 [CRITICAL] CVE-2017-14122: unrar 0 unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a stack-based buffer over-read in unrarlib.c, related to ExtrFile and stricomp.
osv
CVE-2017-14120HIGHCVSS 7.5≥ 0, < 1:0.0.1+cvs20140707-22017-09-03
CVE-2017-14120 [HIGH] CVE-2017-14120: unrar 0 unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a directory traversal vulnerability for RAR v2 archives: pathnames of the form ../[filename] are unpacked into the upper directory.
osv
CVE-2017-14121MEDIUMCVSS 6.5≥ 0, < 1:0.0.1+cvs20140707-42017-09-03
CVE-2017-14121 [MEDIUM] CVE-2017-14121: The DecodeNumber function in unrarlib The DecodeNumber function in unrarlib.c in unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a NULL pointer dereference flaw triggered by a crafted RAR archive. NOTE: this may be the same as one of the several test cases in the CVE-2017-11189 references.
osv
CVE-2017-11190HIGHCVSS 7.8v0.0.12017-07-12
CVE-2017-11190 [HIGH] CWE-119 CVE-2017-11190: unrarlib.c in unrar-free 0.0.1, when _DEBUG_LOG mode is enabled, might allow remote attackers to cau unrarlib.c in unrar-free 0.0.1, when _DEBUG_LOG mode is enabled, might allow remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via an RAR archive containing a long filename.
nvdosv
CVE-2017-11189MEDIUMCVSS 6.5v0.0.12017-07-12
CVE-2017-11189 [MEDIUM] CWE-476 CVE-2017-11189: unrarlib.c in unrar-free 0.0.1 might allow remote attackers to cause a denial of service (NULL point unrarlib.c in unrar-free 0.0.1 might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash), which could be relevant if unrarlib is used as library code for a long-running application. NOTE: one of the several test cases in the references may be the same as what was separately reported as CVE-2017-14121.
nvdosv