Midnight Commander is a widely deployed terminal-based file manager and system utility that operates across Unix and Linux environments, maintaining a role in system administration and remote access workflows despite the emergence of modern alternatives. The vulnerability disclosures associated with this vendor, while modest in volume relative to larger platforms, reflect its long operational history and continued presence in production environments. The recorded weakness classes for this vendor are categorized under broad placeholders in the National Vulnerability Database, limiting structural pattern visibility; however, the vendor's core function—text-based file and system navigation—suggests exposure patterns typical of command-line tools handling user input and filesystem operations. Defenders should treat Midnight Commander vulnerabilities according to their deployment context: instances exposed over SSH or used in multi-user systems warrant priority review, while isolated local instances present lower risk. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Midnight Commander over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0226HIGH Multiple buffer overflows in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code. | Aug 18, 2004 | 10.0 | 26 | NO | NO |
CVE-2003-1023HIGH Stack-based buffer overflow in vfs_s_resolve_symlink of vfs/direntry.c for Midnight Commander (mc) 4.6.0 and earlier, and possibly later versions, allows remote attackers to execut | Jan 20, 2004 | 7.5 | 26 | NO | NO |
CVE-2021-36370HIGH An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection, the fingerprint of the server is neither checked nor displayed. As a result, a u | Aug 30, 2021 | 7.5 | 25 | NO | NO |
CVE-2004-1005HIGH Multiple buffer overflows in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact. | Apr 14, 2005 | 7.5 | 20 | NO | NO |
CVE-2004-1176HIGH Buffer underflow in extfs.c in Midnight Commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code. | Apr 14, 2005 | 7.5 | 20 | NO | NO |
CVE-2004-1004HIGH Multiple format string vulnerabilities in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact. | Apr 14, 2005 | 7.5 | 19 | NO | NO |
CVE-2004-1175HIGH fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacters. | Apr 14, 2005 | 7.5 | 19 | NO | NO |
CVE-2012-4463MEDIUM Midnight Commander (mc) 4.8.5 does not properly handle the (1) MC_EXT_SELECTED or (2) MC_EXT_ONLYTAGGED environment variables when multiple files are selected, which allows user-as | Oct 10, 2012 | 5.1 | 18 | NO | NO |
CVE-2004-1009MEDIUM Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors. | Apr 14, 2005 | 5.0 | 17 | NO | NO |
CVE-2004-0232MEDIUM Multiple format string vulnerabilities in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code. | Aug 18, 2004 | 5.0 | 17 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Midnight Commander.
Media articles that mention a CVE ID that affects a product developed by Midnight Commander — matched by CVE ID, not by vendor name.