CVE-2005-0331
UnknownEPSS 1.45%
Last modified
CVE-2005-0331 is a vulnerability of currently unknown severity. Directory traversal vulnerability in WinRAR 3.42 and earlier, when the user clicks on the ZIP file to extract it, allows remote attackers to create arbitrary files via a ... (triple dot) in the filename of the ZIP file.. EPSS estimates a 1.45% chance of exploitation in the next 30 days.
Description
Directory traversal vulnerability in WinRAR 3.42 and earlier, when the user clicks on the ZIP file to extract it, allows remote attackers to create arbitrary files via a ... (triple dot) in the filename of the ZIP file.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rarlab | Winrar | 3.0.0 |
| Rarlab | Winrar | 3.10 |
| Rarlab | Winrar | 3.10_beta3 |
| Rarlab | Winrar | 3.10_beta5 |
| Rarlab | Winrar | 3.11 |
| Rarlab | Winrar | 3.20 |
| Rarlab | Winrar | 3.40 |
| Rarlab | Winrar | 3.41 |
| Rarlab | Winrar | 3.42 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-0331?
Directory traversal vulnerability in WinRAR 3.42 and earlier, when the user clicks on the ZIP file to extract it, allows remote attackers to create arbitrary files via a ... (triple dot) in the filename of the ZIP file.
How severe is CVE-2005-0331?
Severity scoring for CVE-2005-0331 is pending analysis. The EPSS model estimates a 1.45% probability of exploitation in the next 30 days.
How do I fix CVE-2005-0331?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-0325Xpand Rally 1.0.0.0 allows remote attackers or remote malici…
- CVE-2005-0326pafiledb.php in PaFileDB 3.1 allows remote attackers to gain…
- CVE-2005-0327pafiledb.php in Pafiledb 3.1 may allow remote attackers to e…
- CVE-2005-0328Zyxel P310, P314, P324 and Netgear RT311, RT314 running the …
- CVE-2005-0329Directory traversal vulnerability in ZipGenius 5.5 and earli…
- CVE-2005-0330Buffer overflow in Painkiller 1.35 and earlier, and possibly…
- CVE-2005-0332Directory traversal vulnerability in DeskNow Mail and Collab…
- CVE-2005-0333LANChat Pro Revival 1.666c allows remote attackers to cause …
- CVE-2005-0334Linksys PSUS4 running firmware 6032 allows remote attackers …
- CVE-2005-0335Directory traversal vulnerability in EMotion MediaPartner We…
- CVE-2005-0336Cross-site scripting (XSS) vulnerability in EMotion MediaPar…
- CVE-2005-0337Postfix 2.1.3, when /proc/net/if_inet6 is not available and …
Are you affected by CVE-2005-0331?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
