Vulnerabilities > Rarlab > High

DATE CVE VULNERABILITY TITLE RISK
2017-08-18 CVE-2017-12938 Path Traversal vulnerability in Rarlab Unrar 0.0.1/5.5.4/5.5.6
UnRAR before 5.5.7 allows remote attackers to bypass a directory-traversal protection mechanism via vectors involving a symlink to the .
network
low complexity
rarlab CWE-22
7.5
2015-12-30 CVE-2015-5663 Permissions, Privileges, and Access Controls vulnerability in Rarlab Winrar 5.30
The file-execution functionality in WinRAR before 5.30 beta 5 allows local users to gain privileges via a Trojan horse file with a name similar to an extensionless filename that was selected by the user.
local
high complexity
rarlab CWE-264
7.4