
CVE-2000-1109
https://notcve.org/view.php?id=CVE-2000-1109
09 Jan 2001 — Midnight Commander (mc) 4.5.51 and earlier does not properly process malformed directory names when a user opens a directory, which allows other local users to gain privileges by creating directories that contain special characters followed by the commands to be executed. • http://archives.neohapsis.com/archives/bugtraq/2000-11/0373.html •

CVE-1999-1337
https://notcve.org/view.php?id=CVE-1999-1337
01 Aug 1999 — FTP client in Midnight Commander (mc) before 4.5.11 stores usernames and passwords for visited sites in plaintext in the world-readable history file, which allows other local users to gain privileges. • http://marc.info/?l=bugtraq&m=93370073207984&w=2 •

CVE-1999-0480
https://notcve.org/view.php?id=CVE-1999-0480
01 Apr 1999 — Local attackers can conduct a denial of service in Midnight Commander 4.x with a symlink attack. • https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0480 •