← Vulnerability feed

Vulnerability record · CVE-2005-3214 · published 14 October 2005

CVE-2005-3214: Alwil avast antivirus vulnerability

Alwil · Avast Antivirus

Multiple interpretation error in unspecified versions of Avast Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

5.1 CVSS 2.0 Medium EPSS 1.7% · top 23.4%
5.1CVSS 2.0 base score
1.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

Multiple interpretation error in unspecified versions of Avast Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.

AV:N/AC:H/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-3214 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-2869Alwil avast antivirus vulnerabilityUnspecified vulnerability in the CHM unpacker in avast! before 4.7.844 has unknown impact and remote attack vectors.EPSS 1.7%7.5CVE-2006-4626Alwil avast antivirus vulnerabilityHeap-based buffer overflow in alwil avast! Anti-virus Engine before 4.7.869 allows remote attackers to execute arbitrary code via a crafted LHA file …EPSS 4.7%7.5CVE-2005-2385Alwil avast antivirus vulnerabilityBuffer overflow in a third-party compression library (UNACEV2.DLL), as used in avast! Antivirus Home/Professional Edition 4.6.665 and Server Edition …EPSS 4.0%7.5CVE-2005-1719Alwil avast antivirus vulnerabilityUnknown vulnerability in ALWIL avast! antivirus 4 (4.6.6230) and earlier, when running on Windows NT 4.0, does not properly detect certain viruses.EPSS 1.4%7.2CVE-2006-1355Alwil avast antivirus vulnerabilityavast! Antivirus 4.6.763 and earlier sets "BUILTIN\Everyone" permissions to critical system files in the installation folder, which allows local user…EPSS 0.39%7.2CVE-2005-1770Alwil avast antivirus memory buffer overflow vulnerabilityBuffer overflow in the Aavmker4 device driver in Avast! Antivirus 4.6 and possibly other versions allows local users to cause a denial of service (sy…EPSS 0.68%5.0CVE-2005-2384Alwil avast antivirus vulnerabilityDirectory traversal vulnerability in a third-party compression library (UNACEV2.DLL), as used in avast! Antivirus Home/Professional Edition 4.6.665 a…EPSS 3.5%4.9CVE-2006-1892Alwil avast antivirus vulnerabilityavast! 4 Linux Home Edition 1.0.5 allows local users to modify permissions of arbitrary files via a symlink attack on the /tmp/_avast4_ temporary dir…EPSS 0.49%

Source: NIST National Vulnerability Database (record CVE-2005-3214), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.