Vulnerabilities > Midnight Commander

DATE CVE VULNERABILITY TITLE RISK
2005-04-14 CVE-2004-1009 Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors. 5.0
2005-04-14 CVE-2004-1005 Multiple buffer overflows in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact. 7.5
2005-04-14 CVE-2004-1004 Multiple format string vulnerabilities in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact. 7.5
2004-08-18 CVE-2004-0232 Multiple format string vulnerabilities in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.
network
low complexity
midnight-commander sgi gentoo slackware
5.0
2004-08-18 CVE-2004-0231 Multiple vulnerabilities in Midnight Commander (mc) before 4.6.0, with unknown impact, related to "Insecure temporary file and directory creations."
local
low complexity
midnight-commander sgi gentoo slackware
2.1
2004-08-18 CVE-2004-0226 Multiple buffer overflows in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.
network
low complexity
midnight-commander sgi gentoo slackware
critical
10.0
2004-01-20 CVE-2003-1023 Buffer Overflow vulnerability in Midnight Commander Midnight Commander 4.5.52/4.5.55/4.6
Stack-based buffer overflow in vfs_s_resolve_symlink of vfs/direntry.c for Midnight Commander (mc) 4.6.0 and earlier, and possibly later versions, allows remote attackers to execute arbitrary code during symlink conversion.
network
low complexity
midnight-commander
7.5
2001-11-12 CVE-2001-1429 Denial-Of-Service vulnerability in Midnight Commander Midnight Commander 4.5.1
Buffer overflow in mcedit in Midnight Commander 4.5.1 allows local users to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a crafted text file.
local
low complexity
midnight-commander
4.6
2001-01-09 CVE-2000-1109 Unspecified vulnerability in Midnight Commander Midnight Commander
Midnight Commander (mc) 4.5.51 and earlier does not properly process malformed directory names when a user opens a directory, which allows other local users to gain privileges by creating directories that contain special characters followed by the commands to be executed.
local
low complexity
midnight-commander
4.6
2001-01-09 CVE-2000-1108 Unspecified vulnerability in Midnight Commander Midnight Commander 4.5.42
cons.saver in Midnight Commander (mc) 4.5.42 and earlier does not properly verify if an output file descriptor is a TTY, which allows local users to corrupt files by creating a symbolic link to the target file, calling mc, and specifying that link as a TTY argument.
local
low complexity
midnight-commander
4.6