Vulnerabilities > Midnight Commander > Midnight Commander > 4.8.5

DATE CVE VULNERABILITY TITLE RISK
2021-08-30 CVE-2021-36370 Improper Authentication vulnerability in Midnight-Commander Midnight Commander
An issue was discovered in Midnight Commander through 4.8.26.
network
low complexity
midnight-commander CWE-287
5.0
2012-10-10 CVE-2012-4463 Improper Input Validation vulnerability in Midnight-Commander Midnight Commander 4.8.5
Midnight Commander (mc) 4.8.5 does not properly handle the (1) MC_EXT_SELECTED or (2) MC_EXT_ONLYTAGGED environment variables when multiple files are selected, which allows user-assisted remote attackers to execute arbitrary commands via a crafted file name.
network
high complexity
midnight-commander CWE-20
5.1