Page 3 of 23 results (0.001 seconds)

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 1

09 Jan 2001 — cons.saver in Midnight Commander (mc) 4.5.42 and earlier does not properly verify if an output file descriptor is a TTY, which allows local users to corrupt files by creating a symbolic link to the target file, calling mc, and specifying that link as a TTY argument. • http://archives.neohapsis.com/archives/bugtraq/2000-11/0192.html •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

01 Aug 1999 — FTP client in Midnight Commander (mc) before 4.5.11 stores usernames and passwords for visited sites in plaintext in the world-readable history file, which allows other local users to gain privileges. • http://marc.info/?l=bugtraq&m=93370073207984&w=2 •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

01 Apr 1999 — Local attackers can conduct a denial of service in Midnight Commander 4.x with a symlink attack. • https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0480 •