CVE-2004-0226

Multiple buffer overflows in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.

Published: 2004-08-18 Last update: 2026-04-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2004-0226 is rated High Risk (73.9/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 3.94%). Core evidence: EPSS rose +2.76% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2004-0226

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 1.18% 3.94% +2.76%
2 2025-03-30 3.45% 1.18% -2.28%
3 2025-03-29 3.45%

Full EPSS history (8 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2004-0226

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
10.0 2.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
10.0 10.0 [email protected]

Weakness enumeration for CVE-2004-0226

OS Trackers for CVE-2004-0226

vendor priority summary link
debian not yet assigned CVE-2004-0226 not yet assigned priority: Debian including 1 source packages (mc), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2004-0226
redhat high https://access.redhat.com/security/cve/CVE-2004-0226
suse medium https://www.suse.com/security/cve/CVE-2004-0226/
ubuntu medium CVE-2004-0226 medium priority: Ubuntu including 1 source packages (mc), 4 status rows across 4 suites (dapper, edgy, feisty, upstream): released 3, needs-triage 1. https://ubuntu.com/security/CVE-2004-0226

Affected software / configurations for CVE-2004-0226

Vendor Product Version Raw CPE
midnight_commander midnight_commander 4.5.40 cpe:2.3:a:midnight_commander:midnight_commander:4.5.40:*:*:*:*:*:*:*
midnight_commander midnight_commander 4.5.41 cpe:2.3:a:midnight_commander:midnight_commander:4.5.41:*:*:*:*:*:*:*
midnight_commander midnight_commander 4.5.42 cpe:2.3:a:midnight_commander:midnight_commander:4.5.42:*:*:*:*:*:*:*
midnight_commander midnight_commander 4.5.43 cpe:2.3:a:midnight_commander:midnight_commander:4.5.43:*:*:*:*:*:*:*
midnight_commander midnight_commander 4.5.44 cpe:2.3:a:midnight_commander:midnight_commander:4.5.44:*:*:*:*:*:*:*
midnight_commander midnight_commander 4.5.45 cpe:2.3:a:midnight_commander:midnight_commander:4.5.45:*:*:*:*:*:*:*
midnight_commander midnight_commander 4.5.46 cpe:2.3:a:midnight_commander:midnight_commander:4.5.46:*:*:*:*:*:*:*
midnight_commander midnight_commander 4.5.47 cpe:2.3:a:midnight_commander:midnight_commander:4.5.47:*:*:*:*:*:*:*
midnight_commander midnight_commander 4.5.48 cpe:2.3:a:midnight_commander:midnight_commander:4.5.48:*:*:*:*:*:*:*
midnight_commander midnight_commander 4.5.49 cpe:2.3:a:midnight_commander:midnight_commander:4.5.49:*:*:*:*:*:*:*
midnight_commander midnight_commander 4.5.50 cpe:2.3:a:midnight_commander:midnight_commander:4.5.50:*:*:*:*:*:*:*
midnight_commander midnight_commander 4.5.51 cpe:2.3:a:midnight_commander:midnight_commander:4.5.51:*:*:*:*:*:*:*
midnight_commander midnight_commander 4.5.52 cpe:2.3:a:midnight_commander:midnight_commander:4.5.52:*:*:*:*:*:*:*
midnight_commander midnight_commander 4.5.55 cpe:2.3:a:midnight_commander:midnight_commander:4.5.55:*:*:*:*:*:*:*
midnight_commander midnight_commander 4.6 cpe:2.3:a:midnight_commander:midnight_commander:4.6:*:*:*:*:*:*:*
sgi propack 2.3 cpe:2.3:a:sgi:propack:2.3:*:*:*:*:*:*:*
sgi propack 2.4 cpe:2.3:a:sgi:propack:2.4:*:*:*:*:*:*:*
gentoo linux 0.5 cpe:2.3:o:gentoo:linux:0.5:*:*:*:*:*:*:*
gentoo linux 0.7 cpe:2.3:o:gentoo:linux:0.7:*:*:*:*:*:*:*
gentoo linux 1.1a cpe:2.3:o:gentoo:linux:1.1a:*:*:*:*:*:*:*
gentoo linux 1.2 cpe:2.3:o:gentoo:linux:1.2:*:*:*:*:*:*:*
gentoo linux 1.4 cpe:2.3:o:gentoo:linux:1.4:*:*:*:*:*:*:*
gentoo linux 1.4 cpe:2.3:o:gentoo:linux:1.4:rc1:*:*:*:*:*:*
gentoo linux 1.4 cpe:2.3:o:gentoo:linux:1.4:rc2:*:*:*:*:*:*
gentoo linux 1.4 cpe:2.3:o:gentoo:linux:1.4:rc3:*:*:*:*:*:*
slackware slackware_linux cpe:2.3:o:slackware:slackware_linux:*:*:*:*:*:*:*:*
slackware slackware_linux 9.0 cpe:2.3:o:slackware:slackware_linux:9.0:*:*:*:*:*:*:*
slackware slackware_linux 9.1 cpe:2.3:o:slackware:slackware_linux:9.1:*:*:*:*:*:*:*

References for CVE-2004-0226

cvelogic Threat Intelligence