RAR Password Recovery 1.80 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload in the registration dialog. Attackers can craft a malicious input string exceeding 6000 bytes and paste it into the User Name and Registration Code field to trigger an application crash.
Metrics
Affected Vendors & Products
References
History
Wed, 11 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Mar 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | RAR Password Recovery 1.80 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload in the registration dialog. Attackers can craft a malicious input string exceeding 6000 bytes and paste it into the User Name and Registration Code field to trigger an application crash. | |
| Title | RAR Password Recovery 1.80 Denial of Service Buffer Overflow | |
| Weaknesses | CWE-787 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-11T19:31:01.490Z
Reserved: 2026-02-23T12:12:58.687Z
Link: CVE-2019-25477
Updated: 2026-03-11T19:22:43.067Z
Status : Received
Published: 2026-03-11T19:16:01.787
Modified: 2026-03-11T19:16:01.787
Link: CVE-2019-25477
No data.
OpenCVE Enrichment
No data.