Loading
WinRAR 3.40, and possibly earlier versions, allows remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename, possibly causing an integer overflow that leads to a buffer overflow.
Use Rarlab vendor hub and Winrar product page to widen CVE-2004-1254 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-8088, CVE-2025-6218 and CVE-2023-38831 for nearby disclosures in the same product family.