Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Midnight Commander

First CVE: Apr 1, 1999Active for: 27 yearsTotal CVEs: 22
23.7
VTI Score
Low

Midnight Commander is a widely deployed terminal-based file manager and system utility that operates across Unix and Linux environments, maintaining a role in system administration and remote access workflows despite the emergence of modern alternatives. The vulnerability disclosures associated with this vendor, while modest in volume relative to larger platforms, reflect its long operational history and continued presence in production environments. The recorded weakness classes for this vendor are categorized under broad placeholders in the National Vulnerability Database, limiting structural pattern visibility; however, the vendor's core function—text-based file and system navigation—suggests exposure patterns typical of command-line tools handling user input and filesystem operations. Defenders should treat Midnight Commander vulnerabilities according to their deployment context: instances exposed over SSH or used in multi-user systems warrant priority review, while isolated local instances present lower risk. Current severity, exploitation status, and exposure counts are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 96% of tracked vendors
3.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
5.6
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Midnight Commander over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 1, 1999
27 years ago
Most Recent CVE
Aug 30, 2021
1,789 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2004-0226HIGH
Multiple buffer overflows in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.
Aug 18, 200410.026NONO
CVE-2003-1023HIGH
Stack-based buffer overflow in vfs_s_resolve_symlink of vfs/direntry.c for Midnight Commander (mc) 4.6.0 and earlier, and possibly later versions, allows remote attackers to execut
Jan 20, 20047.526NONO
CVE-2021-36370HIGH
An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection, the fingerprint of the server is neither checked nor displayed. As a result, a u
Aug 30, 20217.525NONO
CVE-2004-1005HIGH
Multiple buffer overflows in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.
Apr 14, 20057.520NONO
CVE-2004-1176HIGH
Buffer underflow in extfs.c in Midnight Commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.
Apr 14, 20057.520NONO
CVE-2004-1004HIGH
Multiple format string vulnerabilities in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.
Apr 14, 20057.519NONO
CVE-2004-1175HIGH
fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacters.
Apr 14, 20057.519NONO
CVE-2012-4463MEDIUM
Midnight Commander (mc) 4.8.5 does not properly handle the (1) MC_EXT_SELECTED or (2) MC_EXT_ONLYTAGGED environment variables when multiple files are selected, which allows user-as
Oct 10, 20125.118NONO
CVE-2004-1009MEDIUM
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.
Apr 14, 20055.017NONO
CVE-2004-0232MEDIUM
Multiple format string vulnerabilities in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.
Aug 18, 20045.017NONO
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
9%
59%
32%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network1 (4.5%)
Unknown21 (95.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (4.5%)
High0 (0.0%)
Unknown21 (95.5%)
User Interaction
None1 (4.5%)
Unknown21 (95.5%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (4.5%)
Unknown21 (95.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Midnight Commander.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Midnight Commander — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Midnight Commander's Products

View all 3 CNAs →

Top CWEs