Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2577▼ 311 respecto a la semana anterior
Críticas / altas1352▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Sin puntuar | 0.32% | — | GNU Midnight CommanderAI | 27/3/2024 | 17/6/2026 | GNU Midnight Commander 4.8.29-146-g299d9a2fb was discovered to contain a NULL pointer dereference via the function x_error_handler() at tty/x11conn.c. NOTE: this is disputed because it should be categorized as a usability problem (an X operation silently fails). | |
| Modificada | Alta (7.5) | 2.0% | — | Midnight-commander Midnight Commander | 30/8/2021 | 17/6/2026 | An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection, the fingerprint of the server is neither checked nor displayed. As a result, a user connects to the server without the ability to verify its authenticity. | |
| Modificada | Media (5.1) | 1.9% | — | Midnight-commander Midnight Commander | 10/10/2012 | 16/6/2026 | Midnight Commander (mc) 4.8.5 does not properly handle the (1) MC_EXT_SELECTED or (2) MC_EXT_ONLYTAGGED environment variables when multiple files are selected, which allows user-assisted remote attackers to execute arbitrary commands via a crafted file name. | |
| Modificada | Media (4.6) | 0.47% | — | Midnight Commander | 2/5/2005 | 16/6/2026 | Buffer overflow in Midnight Commander (mc) 4.5.55 and earlier may allow attackers to execute arbitrary code. | |
| Modificada | Media (5) | 1.7% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "a corrupt section header." | |
| Modificada | Media (5) | 1.7% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "use of already freed memory." | |
| Modificada | Alta (7.5) | 1.6% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | Multiple format string vulnerabilities in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact. | |
| Modificada | Alta (7.5) | 1.8% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | Multiple buffer overflows in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact. | |
| Modificada | Media (5) | 1.7% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by causing mc to free unallocated memory. | |
| Modificada | Alta (7.5) | 3.1% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | Buffer underflow in extfs.c in Midnight Commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code. | |
| Modificada | Media (5) | 1.4% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | direntry.c in Midnight Commander (mc) 4.5.55 and earlier allows attackers to cause a denial of service by "manipulating non-existing file handles." | |
| Modificada | Media (5) | 1.7% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by triggering a null dereference. | |
| Modificada | Alta (7.5) | 1.6% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacters. | |
| Modificada | Media (5) | 2.5% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors. | |
| Modificada | Media (5) | 2.9% | — | Midnight CommanderSGI PropackGentoo LinuxSlackware Linux | 18/8/2004 | 16/6/2026 | Multiple format string vulnerabilities in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code. | |
| Modificada | Baja (2.1) | 0.38% | — | Midnight CommanderSGI PropackGentoo LinuxSlackware Linux | 18/8/2004 | 16/6/2026 | Multiple vulnerabilities in Midnight Commander (mc) before 4.6.0, with unknown impact, related to "Insecure temporary file and directory creations." | |
| Modificada | Alta (10) | 3.9% | — | Midnight CommanderSGI PropackGentoo LinuxSlackware Linux | 18/8/2004 | 16/6/2026 | Multiple buffer overflows in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code. | |
| Modificada | Alta (7.5) | 5.1% | — | Midnight Commander | 20/1/2004 | 16/6/2026 | Stack-based buffer overflow in vfs_s_resolve_symlink of vfs/direntry.c for Midnight Commander (mc) 4.6.0 and earlier, and possibly later versions, allows remote attackers to execute arbitrary code during symlink conversion. | |
| Modificada | Media (4.6) | 0.44% | — | Midnight Commander | 12/11/2001 | 16/6/2026 | Buffer overflow in mcedit in Midnight Commander 4.5.1 allows local users to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a crafted text file. | |
| Modificada | Media (4.6) | 0.34% | — | Midnight Commander | 9/1/2001 | 16/6/2026 | Midnight Commander (mc) 4.5.51 and earlier does not properly process malformed directory names when a user opens a directory, which allows other local users to gain privileges by creating directories that contain special characters followed by the commands to be executed. | |
| Modificada | Media (4.6) | 0.44% | — | Midnight Commander | 9/1/2001 | 16/6/2026 | cons.saver in Midnight Commander (mc) 4.5.42 and earlier does not properly verify if an output file descriptor is a TTY, which allows local users to corrupt files by creating a symbolic link to the target file, calling mc, and specifying that link as a TTY argument. | |
| Modificada | Media (4.6) | 0.33% | — | Midnight Commander | 1/8/1999 | 16/6/2026 | FTP client in Midnight Commander (mc) before 4.5.11 stores usernames and passwords for visited sites in plaintext in the world-readable history file, which allows other local users to gain privileges. | |
| Modificada | Baja (2.1) | 0.34% | — | Midnight Commander | 1/4/1999 | 16/6/2026 | Local attackers can conduct a denial of service in Midnight Commander 4.x with a symlink attack. |