Skip to content
Appaloosa Scout

Vulnerability · NVD

CVE-2005-3262

N/A

Format string vulnerability in RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via format string specifiers in a UUE/XXE file, which are not properly handled when WinRAR displays diagnostic errors related to an invalid filename.

EPSS 8.80% above median percentile 94.7%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

  • WinRAR Windows winget:RARLab.WinRAR
    Affected Fixed in Latest tracked 7.23.0 undetermined
Vulnerable CPE configurations (11)
Vendor Product Versions
rarlab winrar
All platforms (wildcard)
rarlab winrar
All platforms (wildcard)
rarlab winrar
All platforms (wildcard)
rarlab winrar
All platforms (wildcard)
rarlab winrar
All platforms (wildcard)
rarlab winrar
All platforms (wildcard)
rarlab winrar
All platforms (wildcard)
rarlab winrar
All platforms (wildcard)
rarlab winrar
All platforms (wildcard)
rarlab winrar
All platforms (wildcard)
rarlab winrar
All platforms (wildcard)
View on NVD ↗ Advisory · secunia.com Advisory · www.securityfocus.com