2.6

CVE-2005-0331

Directory traversal vulnerability in WinRAR 3.42 and earlier, when the user clicks on the ZIP file to extract it, allows remote attackers to create arbitrary files via a ... (triple dot) in the filename of the ZIP file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
RARLAB ≫ WinRAR Version 3.0.0
RARLAB ≫ WinRAR Version 3.10
RARLAB ≫ WinRAR Version 3.10_beta3
RARLAB ≫ WinRAR Version 3.10_beta5
RARLAB ≫ WinRAR Version 3.11
RARLAB ≫ WinRAR Version 3.20
RARLAB ≫ WinRAR Version 3.40
RARLAB ≫ WinRAR Version 3.41
RARLAB ≫ WinRAR Version 3.42
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.45% 0.698
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 2.6 4.9 2.9
AV:N/AC:H/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://marc.info/?l=bugtraq&m=110737609604210&w=2
http://www.securityfocus.com/bid/12422
https://exchange.xforce.ibmcloud.com/vulnerabilities/20585