This page aggregates publicly disclosed CVE and security risk information related to midnight_commander, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2005-0763 | Buffer overflow in Midnight Commander (mc) 4.5.55 and earlier may allow attackers to execute arbitrary code. | [email protected] | 4.6 | 0.10% | 2005-05-02 | 2026-04-16 |
| CVE-2004-1176 | Buffer underflow in extfs.c in Midnight Commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code. | [email protected] | 7.5 | 2.21% | 2005-04-14 | 2026-04-16 |
| CVE-2004-1175 | fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacters. | [email protected] | 7.5 | 0.95% | 2005-04-14 | 2026-04-16 |
| CVE-2004-1174 | direntry.c in Midnight Commander (mc) 4.5.55 and earlier allows attackers to cause a denial of service by "manipulating non-existing file handles." | [email protected] | 5.0 | 1.14% | 2005-04-14 | 2026-04-16 |
| CVE-2004-1093 | Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "use of already freed memory." | [email protected] | 5.0 | 1.06% | 2005-04-14 | 2026-04-16 |
| CVE-2004-1092 | Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by causing mc to free unallocated memory. | [email protected] | 5.0 | 0.76% | 2005-04-14 | 2026-04-16 |
| CVE-2004-1091 | Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by triggering a null dereference. | [email protected] | 5.0 | 1.06% | 2005-04-14 | 2026-04-16 |
| CVE-2004-1090 | Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "a corrupt section header." | [email protected] | 5.0 | 1.06% | 2005-04-14 | 2026-04-16 |
| CVE-2004-1009 | Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors. | [email protected] | 5.0 | 1.29% | 2005-04-14 | 2026-04-16 |
| CVE-2004-1005 | Multiple buffer overflows in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact. | [email protected] | 7.5 | 1.11% | 2005-04-14 | 2026-04-16 |
| CVE-2004-1004 | Multiple format string vulnerabilities in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact. | [email protected] | 7.5 | 0.95% | 2005-04-14 | 2026-04-16 |
| CVE-2004-0232 | Multiple format string vulnerabilities in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code. | [email protected] | 5.0 | 1.03% | 2004-08-18 | 2026-04-16 |
| CVE-2004-0231 | Multiple vulnerabilities in Midnight Commander (mc) before 4.6.0, with unknown impact, related to "Insecure temporary file and directory creations." | [email protected] | 2.1 | 0.08% | 2004-08-18 | 2026-04-16 |
| CVE-2004-0226 | Multiple buffer overflows in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code. | [email protected] | 10.0 | 1.18% | 2004-08-18 | 2026-04-16 |
| CVE-2003-1023 | Stack-based buffer overflow in vfs_s_resolve_symlink of vfs/direntry.c for Midnight Commander (mc) 4.6.0 and earlier, and possibly later versions, allows remote attackers to execute arbitrary code during symlink conversion. | [email protected] | 7.5 | 8.28% | 2004-01-20 | 2026-04-16 |
| CVE-2001-1429 | Buffer overflow in mcedit in Midnight Commander 4.5.1 allows local users to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a crafted text file. | [email protected] | 4.6 | 0.39% | 2001-11-12 | 2026-04-16 |
| CVE-2000-1109 | Midnight Commander (mc) 4.5.51 and earlier does not properly process malformed directory names when a user opens a directory, which allows other local users to gain privileges by creating directories that contain special characters followed by the commands to be executed. | [email protected] | 4.6 | 0.08% | 2001-01-09 | 2026-04-16 |
| CVE-2000-1108 | cons.saver in Midnight Commander (mc) 4.5.42 and earlier does not properly verify if an output file descriptor is a TTY, which allows local users to corrupt files by creating a symbolic link to the target file, calling mc, and specifying that link as a TTY argument. | [email protected] | 4.6 | 0.08% | 2001-01-09 | 2026-04-16 |
| CVE-1999-1337 | FTP client in Midnight Commander (mc) before 4.5.11 stores usernames and passwords for visited sites in plaintext in the world-readable history file, which allows other local users to gain privileges. | [email protected] | 4.6 | 0.08% | 1999-08-01 | 2026-04-16 |
| CVE-1999-0480 | Local attackers can conduct a denial of service in Midnight Commander 4.x with a symlink attack. | [email protected] | 2.1 | 0.06% | 1999-04-01 | 2026-04-16 |