Midnight-Commander Midnight Commander vulnerabilities
2 known vulnerabilities affecting midnight-commander/midnight_commander.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2021-36370HIGHCVSS 7.5≤ 4.8.262021-08-30
CVE-2021-36370 [HIGH] CWE-287 CVE-2021-36370: An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection,
An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection, the fingerprint of the server is neither checked nor displayed. As a result, a user connects to the server without the ability to verify its authenticity.
nvd
CVE-2012-4463MEDIUMCVSS 5.1v4.8.52012-10-10
CVE-2012-4463 [MEDIUM] CWE-20 CVE-2012-4463: Midnight Commander (mc) 4.8.5 does not properly handle the (1) MC_EXT_SELECTED or (2) MC_EXT_ONLYTAG
Midnight Commander (mc) 4.8.5 does not properly handle the (1) MC_EXT_SELECTED or (2) MC_EXT_ONLYTAGGED environment variables when multiple files are selected, which allows user-assisted remote attackers to execute arbitrary commands via a crafted file name.
nvd