Show filters
22 Total Results
Displaying 1-10 of 22
Sort by:
Attacker Value
Unknown
CVE-2021-36370
Disclosure Date: August 30, 2021 (last updated November 28, 2024)
An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection, the fingerprint of the server is neither checked nor displayed. As a result, a user connects to the server without the ability to verify its authenticity.
0
Attacker Value
Unknown
CVE-2012-4463
Disclosure Date: October 10, 2012 (last updated October 05, 2023)
Midnight Commander (mc) 4.8.5 does not properly handle the (1) MC_EXT_SELECTED or (2) MC_EXT_ONLYTAGGED environment variables when multiple files are selected, which allows user-assisted remote attackers to execute arbitrary commands via a crafted file name.
0
Attacker Value
Unknown
CVE-2005-0763
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Buffer overflow in Midnight Commander (mc) 4.5.55 and earlier may allow attackers to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2004-1174
Disclosure Date: April 14, 2005 (last updated February 22, 2025)
direntry.c in Midnight Commander (mc) 4.5.55 and earlier allows attackers to cause a denial of service by "manipulating non-existing file handles."
0
Attacker Value
Unknown
CVE-2004-1175
Disclosure Date: April 14, 2005 (last updated February 22, 2025)
fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacters.
0
Attacker Value
Unknown
CVE-2004-1090
Disclosure Date: April 14, 2005 (last updated February 22, 2025)
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "a corrupt section header."
0
Attacker Value
Unknown
CVE-2004-1009
Disclosure Date: April 14, 2005 (last updated February 22, 2025)
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.
0
Attacker Value
Unknown
CVE-2004-1093
Disclosure Date: April 14, 2005 (last updated February 22, 2025)
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "use of already freed memory."
0
Attacker Value
Unknown
CVE-2004-1004
Disclosure Date: April 14, 2005 (last updated February 22, 2025)
Multiple format string vulnerabilities in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.
0
Attacker Value
Unknown
CVE-2004-1092
Disclosure Date: April 14, 2005 (last updated February 22, 2025)
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by causing mc to free unallocated memory.
0