CVE Tools

Midnight-commander

20 CVEs tracked since 2000. Since Feb 2000, none of them reached CISA KEV.

Midnight-commander CVEs per month

Feb 2000 to Mar 2005. Point at a month, or focus the strip and use the arrow keys.
Midnight-commander CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2000-0210
2000-03null or fewer
2000-04null or fewer
2000-05null or fewer
2000-06null or fewer
2000-07null or fewer
2000-08null or fewer
2000-09null or fewer
2000-10null or fewer
2000-11null or fewer
2000-12null or fewer
2001-01null or fewer
2001-02null or fewer
2001-03null or fewer
2001-04null or fewer
2001-0520
2001-06null or fewer
2001-07null or fewer
2001-08null or fewer
2001-09null or fewer
2001-10null or fewer
2001-11null or fewer
2001-12null or fewer
2002-01null or fewer
2002-02null or fewer
2002-03null or fewer
2002-04null or fewer
2002-05null or fewer
2002-06null or fewer
2002-07null or fewer
2002-08null or fewer
2002-09null or fewer
2002-10null or fewer
2002-11null or fewer
2002-12null or fewer
2003-01null or fewer
2003-02null or fewer
2003-03null or fewer
2003-0410
2003-05null or fewer
2003-06null or fewer
2003-07null or fewer
2003-08null or fewer
2003-09null or fewer
2003-10null or fewer
2003-11null or fewer
2003-12null or fewer
2004-0110
2004-02null or fewer
2004-03null or fewer
2004-04null or fewer
2004-0530
2004-06null or fewer
2004-07null or fewer
2004-08null or fewer
2004-09null or fewer
2004-10null or fewer
2004-11null or fewer
2004-12null or fewer
2005-01100
2005-02null or fewer
2005-0320

Products

The products that kept showing up in Midnight-commander's monthly top three, with their CVEs summed over those months.

  1. Midnight Commander207 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Midnight-commander.

  1. CVE-2005-0763Buffer overflow in Midnight Commander (mc) 4.5.55 and earlier may allow attackers to execute arbitrary code.4.6
  2. CVE-2001-1429Buffer overflow in mcedit in Midnight Commander 4.5.1 allows local users to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a crafted text file.4.6
  3. CVE-2004-1093Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "use of already freed memory."5.0
  4. CVE-2004-1092Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by causing mc to free unallocated memory.5.0
  5. CVE-2004-1174direntry.c in Midnight Commander (mc) 4.5.55 and earlier allows attackers to cause a denial of service by "manipulating non-existing file handles."5.0
  6. CVE-2004-1176Buffer underflow in extfs.c in Midnight Commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.7.5
  7. CVE-2004-1175fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacters.7.5
  8. CVE-2004-1091Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by triggering a null dereference.5.0
  9. CVE-2004-1090Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "a corrupt section header."5.0
  10. CVE-2004-1004Multiple format string vulnerabilities in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.7.5
  11. CVE-2004-1009Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.5.0
  12. CVE-2004-1005Multiple buffer overflows in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.7.5
  13. CVE-2004-0231Multiple vulnerabilities in Midnight Commander (mc) before 4.6.0, with unknown impact, related to "Insecure temporary file and directory creations."2.1
  14. CVE-2004-0226Multiple buffer overflows in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.10.0
  15. CVE-2004-0232Multiple format string vulnerabilities in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.5.0

The record

Peak rank
#10 in May 2004
Busiest month shown
Jan 2005, 10 CVEs
Months with a KEV entry
0 since Feb 2000
Monthly snapshots
7 since 2000
Midnight-commander's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store