Known Vulnerabilities for Unrar by Rarlab
Listed below are 10 of the newest known vulnerabilities associated with "Unrar" by "Rarlab".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2018-25018 | UnRAR 5.6.1.7 through 5.7.4 and 6.0.3 has an out-of-bounds write during a memcpy in QuickOpen::ReadRaw when called from Quick... | 7.8 - HIGH | 2021-07-01 | 2021-07-07 |
| CVE-2017-20006 | UnRAR 5.6.1.2 and 5.6.1.3 has a heap-based buffer overflow in Unpack::CopyString (called from Unpack::Unpack5 and CmdExtract:... | 7.8 - HIGH | 2021-07-01 | 2021-07-07 |
| CVE-2017-14122 | unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a stack-based buffer over-read in unrarlib.c, related to ExtrFile and ... | 9.1 - CRITICAL | 2017-09-03 | 2021-02-25 |
| CVE-2017-14121 | The DecodeNumber function in unrarlib.c in unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a NULL pointer dereference ... | 5.5 - MEDIUM | 2017-09-03 | 2021-10-18 |
| CVE-2017-14120 | unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a directory traversal vulnerability for RAR v2 archives: pathnames of ... | 7.5 - HIGH | 2017-09-03 | 2021-02-25 |
| CVE-2017-12942 | libunrar.a in UnRAR before 5.5.7 has a buffer overflow in the Unpack::LongLZ function. | 9.8 - CRITICAL | 2017-08-18 | 2018-06-16 |
| CVE-2017-12941 | libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the Unpack::Unpack20 function. | 9.8 - CRITICAL | 2017-08-18 | 2018-06-16 |
| CVE-2017-12940 | libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the EncodeFileName::Decode call within the Archive::ReadHeader1... | 9.8 - CRITICAL | 2017-08-18 | 2018-06-16 |
| CVE-2017-12938 | UnRAR before 5.5.7 allows remote attackers to bypass a directory-traversal protection mechanism via vectors involving a symli... | 7.5 - HIGH | 2017-08-18 | 2017-08-29 |
| CVE-2012-6706 | A VMSF_DELTA memory corruption was discovered in unrar before 5.5.5, as used in Sophos Anti-Virus Threat Detection Engine bef... | 9.8 - CRITICAL | 2017-06-22 | 2018-10-21 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Rarlab | Unrar | 0.0.1 | All | All | All |