← Back

Unrar

unrar

Vendor: Rarlab • 14 CVEs

CVEs (14)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Rarlab
1Unrar
Jun 17, 2026
Aug 7, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
UnRAR before 6.2.3 allows extraction of files outside of the destination folder via symlink chains.
2Debian
Rarlab
2Debian Linux
Unrar
Jun 17, 2026
May 9, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR ar...Show more
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.Show less
1Rarlab
1Unrar
Nov 21, 2024
Jul 1, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
UnRAR 5.6.1.7 through 5.7.4 and 6.0.3 has an out-of-bounds write during a memcpy in QuickOpen::ReadRaw when called from QuickOpen::ReadNext.
1Rarlab
1Unrar
Nov 21, 2024
Jul 1, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
UnRAR 5.6.1.2 and 5.6.1.3 has a heap-based buffer overflow in Unpack::CopyString (called from Unpack::Unpack5 and CmdExtract::ExtractCurrentFile).
2Debian
Rarlab
2Debian Linux
Unrar
May 13, 2026
Sep 3, 2017
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a stack-based buffer over-read in unrarlib.c, related to ExtrFile and stricomp.
2Debian
Rarlab
2Debian Linux
Unrar
May 13, 2026
Sep 3, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The DecodeNumber function in unrarlib.c in unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a NULL pointer dereference flaw triggered by a crafted RAR archive. NOTE: this may be the same as one of the several test...Show more
The DecodeNumber function in unrarlib.c in unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a NULL pointer dereference flaw triggered by a crafted RAR archive. NOTE: this may be the same as one of the several test cases in the CVE-2017-11189 references.Show less
2Debian
Rarlab
2Debian Linux
Unrar
May 13, 2026
Sep 3, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a directory traversal vulnerability for RAR v2 archives: pathnames of the form ../[filename] are unpacked into the upper directory.
1Rarlab
1Unrar
May 13, 2026
Aug 18, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
libunrar.a in UnRAR before 5.5.7 has a buffer overflow in the Unpack::LongLZ function.
1Rarlab
1Unrar
May 13, 2026
Aug 18, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the Unpack::Unpack20 function.
1Rarlab
1Unrar
May 13, 2026
Aug 18, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the EncodeFileName::Decode call within the Archive::ReadHeader15 function.
1Rarlab
1Unrar
May 13, 2026
Aug 18, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
UnRAR before 5.5.7 allows remote attackers to bypass a directory-traversal protection mechanism via vectors involving a symlink to the . directory, a symlink to the .. directory, and a regular file.
2Rarlab
Sophos
2Threat Detection Engine
Unrar
May 13, 2026
Jun 22, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A VMSF_DELTA memory corruption was discovered in unrar before 5.5.5, as used in Sophos Anti-Virus Threat Detection Engine before 3.37.2 and other products, that can lead to arbitrary code execution. An integer overflow c...Show more
A VMSF_DELTA memory corruption was discovered in unrar before 5.5.5, as used in Sophos Anti-Virus Threat Detection Engine before 3.37.2 and other products, that can lead to arbitrary code execution. An integer overflow can be caused in DataSize+CurChannel. The result is a negative value of the "DestPos" variable, which allows the attacker to write out of bounds when setting Mem[DestPos].Show less
1Rarlab
1Unrar
Apr 23, 2026
Jul 12, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Integer signedness error in the SET_VALUE function in rarvm.cpp in unrar 3.70 beta 3, as used in products including WinRAR and RAR for OS X, allows user-assisted remote attackers to cause a denial of service (crash) via...Show more
Integer signedness error in the SET_VALUE function in rarvm.cpp in unrar 3.70 beta 3, as used in products including WinRAR and RAR for OS X, allows user-assisted remote attackers to cause a denial of service (crash) via a crafted RAR archive that causes a negative signed number to be cast to a large unsigned number.Show less
1Rarlab
1Unrar
Apr 23, 2026
Feb 8, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Stack-based buffer overflow in RARLabs Unrar, as packaged in WinRAR and possibly other products, allows user-assisted remote attackers to execute arbitrary code via a crafted, password-protected archive.