Synced 16 Jun 2026 15:24 UTC Account
← All products

CVE-2005-0331

LOW severity · CVSS 2.6
2.6CVSS LOW

Summary

Directory traversal vulnerability in WinRAR 3.42 and earlier, when the user clicks on the ZIP file to extract it, allows remote attackers to create arbitrary files via a ... (triple dot) in the filename of the ZIP file.

Impact & exploitability

Attack vectorNetwork
Attack complexityHigh
Privileges required
User interaction
Confidentiality impactNone
Integrity impact
Availability impactNone
Exploit probability (EPSS)1%

AV:N/AC:H/Au:N/C:N/I:P/A:N

Affected products we track (1)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.