9.3

CVE-2006-3845

Exploit

Stack-based buffer overflow in lzh.fmt in WinRAR 3.00 through 3.60 beta 6 allows remote attackers to execute arbitrary code via a long filename in a LHA archive.

Data is provided by the National Vulnerability Database (NVD)
RARLABWinRAR Version3.0.0
RARLABWinRAR Version3.10
RARLABWinRAR Version3.10_beta3
RARLABWinRAR Version3.10_beta5
RARLABWinRAR Version3.11
RARLABWinRAR Version3.20
RARLABWinRAR Version3.30
RARLABWinRAR Version3.40
RARLABWinRAR Version3.41
RARLABWinRAR Version3.42
RARLABWinRAR Version3.50
RARLABWinRAR Version3.51
RARLABWinRAR Version3.60_beta1
RARLABWinRAR Version3.60_beta2
RARLABWinRAR Version3.60_beta3
RARLABWinRAR Version3.60_beta4
RARLABWinRAR Version3.60_beta5
RARLABWinRAR Version3.60_beta6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 5.58% 0.893
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C