Gnu Emacs vulnerabilities
33 known vulnerabilities affecting gnu/emacs.
Total CVEs
33
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH13MEDIUM9LOW8
Vulnerabilities
Page 2 of 2
CVE-2012-3479MEDIUMCVSS 6.8v23.2v23.3+2 more2012-08-25
CVE-2012-3479 [MEDIUM] CVE-2012-3479: lisp/files.el in Emacs 23.2, 23.3, 23.4, and 24.1 automatically executes eval forms in local-variabl
lisp/files.el in Emacs 23.2, 23.3, 23.4, and 24.1 automatically executes eval forms in local-variable sections when the enable-local-variables option is set to :safe, which allows user-assisted remote attackers to execute arbitrary Emacs Lisp code via a crafted file.
nvd
CVE-2012-0035CRITICALCVSS 9.3≤ 23.3v20.0+20 more2012-01-19
CVE-2012-0035 [CRITICAL] CVE-2012-0035: Untrusted search path vulnerability in EDE in CEDET before 1.0.1, as used in GNU Emacs before 23.4 a
Untrusted search path vulnerability in EDE in CEDET before 1.0.1, as used in GNU Emacs before 23.4 and other products, allows local users to gain privileges via a crafted Lisp expression in a Project.ede file in the directory, or a parent directory, of an opened file.
nvd
CVE-2010-0825MEDIUMCVSS 4.4v22.1v22.2+2 more2010-04-05
CVE-2010-0825 [MEDIUM] CWE-264 CVE-2010-0825: lib-src/movemail.c in movemail in emacs 22 and 23 allows local users to read, modify, or delete arbi
lib-src/movemail.c in movemail in emacs 22 and 23 allows local users to read, modify, or delete arbitrary mailbox files via a symlink attack, related to improper file-permission checks.
nvd
CVE-2008-2142MEDIUMCVSS 6.8v21.3.12008-05-12
CVE-2008-2142 [MEDIUM] CVE-2008-2142: Emacs 21 and XEmacs automatically load and execute .flc (fast lock) files that are associated with o
Emacs 21 and XEmacs automatically load and execute .flc (fast lock) files that are associated with other files that are edited within Emacs, which allows user-assisted attackers to execute arbitrary code.
nvd
CVE-2008-1694MEDIUMCVSS 4.6v20.7v21.1+3 more2008-04-22
CVE-2008-1694 [MEDIUM] CWE-59 CVE-2008-1694: vcdiff in Emacs 20.7 to 22.1.50, when used with SCCS, allows local users to overwrite arbitrary file
vcdiff in Emacs 20.7 to 22.1.50, when used with SCCS, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
nvd
CVE-2007-5795MEDIUMCVSS 6.3PoC≤ 22.12007-11-02
CVE-2007-5795 [MEDIUM] CVE-2007-5795: The hack-local-variables function in Emacs before 22.2, when enable-local-variables is set to :safe,
The hack-local-variables function in Emacs before 22.2, when enable-local-variables is set to :safe, does not properly search lists of unsafe or risky variables, which might allow user-assisted attackers to bypass intended restrictions and modify critical program variables via a file containing a Local variables declaration.
nvd
CVE-2007-2833HIGHCVSS 7.8v212007-06-21
CVE-2007-2833 [HIGH] CVE-2007-2833: Emacs 21 allows user-assisted attackers to cause a denial of service (crash) via certain crafted ima
Emacs 21 allows user-assisted attackers to cause a denial of service (crash) via certain crafted images, as demonstrated via a GIF image in vm mode, related to image size calculation.
nvd
CVE-2005-0100HIGHCVSS 7.5≤ 20.0v21.32005-02-07
CVE-2005-0100 [HIGH] CVE-2005-0100: Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other vers
Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.
nvd
CVE-2003-1232MEDIUMCVSS 5.1PoCv21.2.12003-12-31
CVE-2003-1232 [MEDIUM] CVE-2003-1232: Emacs 21.2.1 does not prompt or warn the user before executing Lisp code in the local variables sect
Emacs 21.2.1 does not prompt or warn the user before executing Lisp code in the local variables section of a text file, which allows user-assisted attackers to execute arbitrary commands, as demonstrated using the mode-name variable.
nvd
CVE-2001-1301LOWCVSS 1.2v20.42001-08-07
CVE-2001-1301 [LOW] CVE-2001-1301: rcs2log, as used in Emacs 20.4, xemacs 21.1.10 and other versions before 21.4, and possibly other pa
rcs2log, as used in Emacs 20.4, xemacs 21.1.10 and other versions before 21.4, and possibly other packages, allows local users to modify files of other users via a symlink attack on a temporary file.
nvd
CVE-2000-0271MEDIUMCVSS 4.6v20.0v20.1+5 more2000-04-18
CVE-2000-0271 [MEDIUM] CVE-2000-0271: read-passwd and other Lisp functions in Emacs 20 do not properly clear the history of recently typed
read-passwd and other Lisp functions in Emacs 20 do not properly clear the history of recently typed keys, which allows an attacker to read unencrypted passwords.
nvd
CVE-2000-0270LOWCVSS 3.6v20.0v20.1+5 more2000-04-18
CVE-2000-0270 [LOW] CVE-2000-0270: The make-temp-name Lisp function in Emacs 20 creates temporary files with predictable names, which a
The make-temp-name Lisp function in Emacs 20 creates temporary files with predictable names, which allows attackers to conduct a symlink attack.
nvd
CVE-2000-0269LOWCVSS 2.1v20.0v20.1+5 more2000-04-18
CVE-2000-0269 [LOW] CVE-2000-0269: Emacs 20 does not properly set permissions for a slave PTY device when starting a new subprocess, wh
Emacs 20 does not properly set permissions for a slave PTY device when starting a new subprocess, which allows local users to read or modify communications between Emacs and the subprocess.
nvd
← Previous2 / 2