Show filters
22 Total Results
Displaying 1-10 of 22
Sort by:
Attacker Value
Unknown

CVE-2021-36370

Disclosure Date: August 30, 2021 (last updated November 28, 2024)
An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection, the fingerprint of the server is neither checked nor displayed. As a result, a user connects to the server without the ability to verify its authenticity.
Attacker Value
Unknown

CVE-2012-4463

Disclosure Date: October 10, 2012 (last updated October 05, 2023)
Midnight Commander (mc) 4.8.5 does not properly handle the (1) MC_EXT_SELECTED or (2) MC_EXT_ONLYTAGGED environment variables when multiple files are selected, which allows user-assisted remote attackers to execute arbitrary commands via a crafted file name.
0
Attacker Value
Unknown

CVE-2005-0763

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Buffer overflow in Midnight Commander (mc) 4.5.55 and earlier may allow attackers to execute arbitrary code.
0
Attacker Value
Unknown

CVE-2004-1174

Disclosure Date: April 14, 2005 (last updated February 22, 2025)
direntry.c in Midnight Commander (mc) 4.5.55 and earlier allows attackers to cause a denial of service by "manipulating non-existing file handles."
0
Attacker Value
Unknown

CVE-2004-1175

Disclosure Date: April 14, 2005 (last updated February 22, 2025)
fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacters.
0
Attacker Value
Unknown

CVE-2004-1090

Disclosure Date: April 14, 2005 (last updated February 22, 2025)
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "a corrupt section header."
0
Attacker Value
Unknown

CVE-2004-1009

Disclosure Date: April 14, 2005 (last updated February 22, 2025)
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.
0
Attacker Value
Unknown

CVE-2004-1093

Disclosure Date: April 14, 2005 (last updated February 22, 2025)
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "use of already freed memory."
0
Attacker Value
Unknown

CVE-2004-1004

Disclosure Date: April 14, 2005 (last updated February 22, 2025)
Multiple format string vulnerabilities in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.
0
Attacker Value
Unknown

CVE-2004-1092

Disclosure Date: April 14, 2005 (last updated February 22, 2025)
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by causing mc to free unallocated memory.
0