Vulnerabilities > Rarlab > Critical

DATE CVE VULNERABILITY TITLE RISK
2017-09-03 CVE-2017-14122 Out-of-bounds Read vulnerability in multiple products
unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a stack-based buffer over-read in unrarlib.c, related to ExtrFile and stricomp.
network
low complexity
rarlab debian CWE-125
critical
9.1
2017-08-18 CVE-2017-12942 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Rarlab Unrar 0.0.1/5.5.4/5.5.6
libunrar.a in UnRAR before 5.5.7 has a buffer overflow in the Unpack::LongLZ function.
network
low complexity
rarlab CWE-119
critical
9.8
2017-08-18 CVE-2017-12941 Out-of-bounds Read vulnerability in Rarlab Unrar 0.0.1/5.5.4/5.5.6
libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the Unpack::Unpack20 function.
network
low complexity
rarlab CWE-125
critical
9.8
2017-08-18 CVE-2017-12940 Out-of-bounds Read vulnerability in Rarlab Unrar 0.0.1/5.5.4/5.5.6
libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the EncodeFileName::Decode call within the Archive::ReadHeader15 function.
network
low complexity
rarlab CWE-125
critical
9.8
2017-06-22 CVE-2012-6706 Integer Overflow or Wraparound vulnerability in multiple products
A VMSF_DELTA memory corruption was discovered in unrar before 5.5.5, as used in Sophos Anti-Virus Threat Detection Engine before 3.37.2 and other products, that can lead to arbitrary code execution.
network
low complexity
sophos rarlab CWE-190
critical
9.8