cbcvebase.
CVE-2010-0825
published 2010-04-05

CVE-2010-0825: lib-src/movemail.c in movemail in emacs 22 and 23 allows local users to read, modify, or delete arbitrary mailbox files via a symlink attack, related to…

PriorityP415medium4.4CVSS 2.0
AVLACMAuNCPIPAP
EPSS
0.33%
24.8th percentile
lib-src/movemail.c in movemail in emacs 22 and 23 allows local users to read, modify, or delete arbitrary mailbox files via a symlink attack, related to improper file-permission checks.

Affected

5 ranges
VendorProductVersion rangeFixed in
debianxemacs21< xemacs21 21.4.22-3.1 (bookworm)xemacs21 21.4.22-3.1 (bookworm)
gnuemacs
gnuemacs
gnuemacs
gnuemacs

CVSS provenance

nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv4.4MEDIUM
vendor_debian4.4LOW
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.