10
CVSSv2

CVE-2004-1254

Published: 10/01/2005 Updated: 11/07/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

WinRAR 3.40, and possibly earlier versions, allows remote malicious users to execute arbitrary code via a ZIP file containing a file with a long filename, possibly causing an integer overflow that leads to a buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

rarlab winrar 3.10_beta3

rarlab winrar 3.10_beta5

rarlab winrar 3.0.0

rarlab winrar 3.10

rarlab winrar 3.40

rarlab winrar 3.41

rarlab winrar 3.11

rarlab winrar 3.20

Exploits

/* WinRAR 340 Buffer Overflow POC Thanks to Miguel Tarasco Acuna He has made a wonderful code for Microsoft Windows Vulnerability in Compressed (zipped) Folders (MS04-034) which I edited and made this code by Coded by Vafa Khoshaein - vkhoshain@hotmailcom Vulnerability discovery date : December 10, 2004 Run this code and creat vulnerable_zi ...