Vulnerability Details CVE-2005-3262
Format string vulnerability in RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via format string specifiers in a UUE/XXE file, which are not properly handled when WinRAR displays diagnostic errors related to an invalid filename.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.096
EPSS Ranking 92.5%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2005-3262
-
cpe:2.3:a:rarlab:winrar:2.90
-
cpe:2.3:a:rarlab:winrar:3.0.0
-
cpe:2.3:a:rarlab:winrar:3.10
-
cpe:2.3:a:rarlab:winrar:3.10_beta3
-
cpe:2.3:a:rarlab:winrar:3.10_beta5
-
cpe:2.3:a:rarlab:winrar:3.11
-
cpe:2.3:a:rarlab:winrar:3.20
-
cpe:2.3:a:rarlab:winrar:3.40
-
cpe:2.3:a:rarlab:winrar:3.41
-
cpe:2.3:a:rarlab:winrar:3.42
-
cpe:2.3:a:rarlab:winrar:3.50