Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

53 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)1.1%—Rarlab UnrarDebian Linux3/9/201717/6/2026
The DecodeNumber function in unrarlib.c in unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a NULL pointer dereference flaw triggered by a crafted RAR archive. NOTE: this may be the same as one of the several test cases in the CVE-2017-11189 references.
ModificadaAlta (7.5)2.1%—Rarlab UnrarDebian Linux3/9/201717/6/2026
unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a directory traversal vulnerability for RAR v2 archives: pathnames of the form ../[filename] are unpacked into the upper directory.
ModificadaCrítica (9.8)2.3%—Rarlab Unrar18/8/201717/6/2026
libunrar.a in UnRAR before 5.5.7 has a buffer overflow in the Unpack::LongLZ function.
ModificadaCrítica (9.8)2.2%—Rarlab Unrar18/8/201717/6/2026
libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the Unpack::Unpack20 function.
ModificadaCrítica (9.8)2.2%—Rarlab Unrar18/8/201717/6/2026
libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the EncodeFileName::Decode call within the Archive::ReadHeader15 function.
ModificadaAlta (7.5)3.0%—Rarlab Unrar18/8/201717/6/2026
UnRAR before 5.5.7 allows remote attackers to bypass a directory-traversal protection mechanism via vectors involving a symlink to the . directory, a symlink to the .. directory, and a regular file.
ModificadaCrítica (9.8)10%—Sophos Threat Detection EngineRarlab Unrar22/6/201716/6/2026
A VMSF_DELTA memory corruption was discovered in unrar before 5.5.5, as used in Sophos Anti-Virus Threat Detection Engine before 3.37.2 and other products, that can lead to arbitrary code execution. An integer overflow can be caused in DataSize+CurChannel. The result is a negative value of the "DestPos" variable,…
ModificadaMedia (5.5)1.8%—Rarlab RAR4/6/201717/6/2026
Directory Traversal exists in RAR 4.x and 5.x because an unpack operation follows any symlinks, including symlinks contained in the archive. This allows remote attackers to write to arbitrary files via a crafted archive.
ModificadaAlta (7.4)0.91%—Rarlab Winrar30/12/201517/6/2026
The file-execution functionality in WinRAR before 5.30 beta 5 allows local users to gain privileges via a Trojan horse file with a name similar to an extensionless filename that was selected by the user.
ModificadaAlta (10)2.3%—Rarlab Winrar1/9/200916/6/2026
Multiple unspecified vulnerabilities in RARLAB WinRAR before 3.71 have unknown impact and attack vectors related to crafted (1) ACE, (2) ARJ, (3) BZ2, (4) CAB, (5) GZ, (6) LHA, (7) RAR, (8) TAR, or (9) ZIP files, as demonstrated by the OUSPG PROTOS GENOME test suite for Archive Formats.
ModificadaMedia (4.3)2.1%—Rarlab Unrar12/7/200716/6/2026
Integer signedness error in the SET_VALUE function in rarvm.cpp in unrar 3.70 beta 3, as used in products including WinRAR and RAR for OS X, allows user-assisted remote attackers to cause a denial of service (crash) via a crafted RAR archive that causes a negative signed number to be cast to a large unsigned number.
ModificadaMedia (6.8)4.0%—Rarlab Unrar8/2/200716/6/2026
Stack-based buffer overflow in RARLabs Unrar, as packaged in WinRAR and possibly other products, allows user-assisted remote attackers to execute arbitrary code via a crafted, password-protected archive.
ModificadaBaja (2.1)5.7%💥 ExploitRarlab Winrar28/7/200616/6/2026
Stack-based buffer overflow in the SFX module in WinRAR before 3.60 beta 8 has unspecified vectors and impact.
ModificadaAlta (9.3)7.9%💥 ExploitRarlab Winrar25/7/200616/6/2026
Stack-based buffer overflow in lzh.fmt in WinRAR 3.00 through 3.60 beta 6 allows remote attackers to execute arbitrary code via a long filename in a LHA archive.
ModificadaMedia (4.6)1.5%💥 ExploitRarlab Winrar31/12/200516/6/2026
Buffer overflow in WinRAR 3.50 and earlier allows local users to execute arbitrary code via a long command-line argument. NOTE: because this program executes with the privileges of the invoking user, and because remote programs do not normally have the ability to specify a command-line argument for this program, there…
ModificadaMedia (5.1)2.0%—Rarlab Winrar22/12/200516/6/2026
Buffer overflow in the "Add to archive" command in WinRAR 3.51 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code by tricking the user into adding a file whose filename contains a non-default code page and non-ANSI characters, as demonstrated using a Chinese…
ModificadaAlta (7.5)3.7%—Rarlab Winrar20/10/200516/6/2026
Stack-based buffer overflow in UNACEV2.DLL for RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via an ACE archive containing a file with a long name.
ModificadaAlta (7.5)8.8%💥 ExploitRarlab Winrar20/10/200516/6/2026
Format string vulnerability in RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via format string specifiers in a UUE/XXE file, which are not properly handled when WinRAR displays diagnostic errors related to an invalid filename.
ModificadaMedia (5.1)1.7%—ClamavAIRarlab WinrarAIPowerzio PowerzipAIPkware WinzipAI+114/10/200516/6/2026
Multiple interpretation error in unspecified versions of ClamAV Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are…
ModificadaMedia (5.1)1.7%—UNA AntivirusAIPowerzipAIWinzipAIRarlab WinrarAI+114/10/200516/6/2026
Multiple interpretation error in unspecified versions of UNA Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected…
ModificadaMedia (5.1)1.7%—PowzipAIWinzipAIPanda AntivirusAIRarlab WinrarAI+114/10/200516/6/2026
Multiple interpretation error in unspecified versions of Panda Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are…
ModificadaMedia (5.1)1.7%—Mcafee AntivirusAIPowerzipAIWinzipAIRarlab WinrarAI+114/10/200516/6/2026
Multiple interpretation error in unspecified versions of McAfee Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are…
ModificadaBaja (2.6)1.4%—Rarlab Winrar2/5/200516/6/2026
Directory traversal vulnerability in WinRAR 3.42 and earlier, when the user clicks on the ZIP file to extract it, allows remote attackers to create arbitrary files via a ... (triple dot) in the filename of the ZIP file.
ModificadaAlta (10)10%💥 ExploitRarlab Winrar10/1/200516/6/2026
WinRAR 3.40, and possibly earlier versions, allows remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename, possibly causing an integer overflow that leads to a buffer overflow.
ModificadaBaja (2.6)1.3%—Rarlab Winrar31/12/200416/6/2026
The Repair Archive command in WinRAR 3.40 allows remote attackers to cause a denial of service (application crash) via a corrupt ZIP archive.
Orbitaley — Vulnerabilidades