
CVE-2005-3263
https://notcve.org/view.php?id=CVE-2005-3263
20 Oct 2005 — Stack-based buffer overflow in UNACEV2.DLL for RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via an ACE archive containing a file with a long name. • http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0266.html •

CVE-2005-0331
https://notcve.org/view.php?id=CVE-2005-0331
10 Feb 2005 — Directory traversal vulnerability in WinRAR 3.42 and earlier, when the user clicks on the ZIP file to extract it, allows remote attackers to create arbitrary files via a ... (triple dot) in the filename of the ZIP file. • http://marc.info/?l=bugtraq&m=110737609604210&w=2 •

CVE-2004-1495
https://notcve.org/view.php?id=CVE-2004-1495
31 Dec 2004 — The Repair Archive command in WinRAR 3.40 allows remote attackers to cause a denial of service (application crash) via a corrupt ZIP archive. • http://marc.info/?l=bugtraq&m=109941351432699&w=2 •

CVE-2004-1254 – WinRAR 3.4.1 - Corrupt '.ZIP' File
https://notcve.org/view.php?id=CVE-2004-1254
22 Dec 2004 — WinRAR 3.40, and possibly earlier versions, allows remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename, possibly causing an integer overflow that leads to a buffer overflow. • https://www.exploit-db.com/exploits/694 •