cbcvebase.

Gnu Emacs vulnerabilities

36 known vulnerabilities affecting gnu/emacs.

Total CVEs
36
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH16MEDIUM9LOW8

Vulnerabilities

Page 2 of 2
CVE-2026-6861P4HIGHCVSS 7.1≥ 28.1, ≤ 30.22026-04-22
CVE-2026-6861 [HIGH] CWE-193 CVE-2026-6861: A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs proc A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially crafted SVG (Scalable Vector Graphics) CSS (Cascading Style Sheets) data. A local user could exploit this by convincing a victim to open a malicious SVG file, which may lead to a denial of service (DoS) or potentially information disclosur
nvd
CVE-2024-30205P4HIGHCVSS 7.1fixed in 29.32024-03-25
CVE-2024-30205 [HIGH] CWE-494 CVE-2024-30205: In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mo In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.
nvdosv
CVE-2007-2833P4HIGHCVSS 7.8v212007-06-21
CVE-2007-2833 [HIGH] CVE-2007-2833: Emacs 21 allows user-assisted attackers to cause a denial of service (crash) via certain crafted ima Emacs 21 allows user-assisted attackers to cause a denial of service (crash) via certain crafted images, as demonstrated via a GIF image in vm mode, related to image size calculation.
nvd
CVE-2017-1000383P4MEDIUMCVSS 5.5≤ 25.3.02017-10-31
CVE-2017-1000383 [MEDIUM] CWE-200 CVE-2017-1000383: GNU Emacs version 25.3.1 (and other versions most likely) ignores umask when creating a backup save GNU Emacs version 25.3.1 (and other versions most likely) ignores umask when creating a backup save file ("[ORIGINAL_FILENAME]~") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the emacs binary.
nvd
CVE-2024-30203P4MEDIUMCVSS 5.5fixed in 29.32024-03-25
CVE-2024-30203 [MEDIUM] CVE-2024-30203: In Emacs before 29.3, Gnus treats inline MIME contents as trusted. In Emacs before 29.3, Gnus treats inline MIME contents as trusted.
nvdosv
CVE-2008-1694P4MEDIUMCVSS 4.6v20.7v21.1+3 more2008-04-22
CVE-2008-1694 [MEDIUM] CWE-59 CVE-2008-1694: vcdiff in Emacs 20.7 to 22.1.50, when used with SCCS, allows local users to overwrite arbitrary file vcdiff in Emacs 20.7 to 22.1.50, when used with SCCS, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
nvd
CVE-2010-0825P4MEDIUMCVSS 4.4v22.1v22.2+2 more2010-04-05
CVE-2010-0825 [MEDIUM] CWE-264 CVE-2010-0825: lib-src/movemail.c in movemail in emacs 22 and 23 allows local users to read, modify, or delete arbi lib-src/movemail.c in movemail in emacs 22 and 23 allows local users to read, modify, or delete arbitrary mailbox files via a symlink attack, related to improper file-permission checks.
nvd
CVE-2014-3422P4LOWCVSS 3.3≤ 24.3v20.0+23 more2014-05-08
CVE-2014-3422 [LOW] CWE-59 CVE-2014-3422: lisp/emacs-lisp/find-gc.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary f lisp/emacs-lisp/find-gc.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file under /tmp/esrc/.
nvd
CVE-2014-3421P4LOWCVSS 3.3≤ 24.3v20.0+23 more2014-05-08
CVE-2014-3421 [LOW] CWE-59 CVE-2014-3421: lisp/gnus/gnus-fun.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files lisp/gnus/gnus-fun.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on the /tmp/gnus.face.ppm temporary file.
nvd
CVE-2014-3424P4LOWCVSS 3.3≤ 24.3v20.0+23 more2014-05-08
CVE-2014-3424 [LOW] CWE-59 CVE-2014-3424: lisp/net/tramp-sh.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files v lisp/net/tramp-sh.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/tramp.##### temporary file.
nvd
CVE-2014-3423P4LOWCVSS 3.3≤ 24.3v20.0+23 more2014-05-08
CVE-2014-3423 [LOW] CWE-59 CVE-2014-3423: lisp/net/browse-url.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files lisp/net/browse-url.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/Mosaic.##### temporary file.
nvd
CVE-2024-30204P4LOWCVSS 2.8fixed in 29.32024-03-25
CVE-2024-30204 [LOW] CWE-276 CVE-2024-30204: In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments. In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.
nvdosv
CVE-2000-0271P4MEDIUMCVSS 4.6v20.0v20.1+5 more2000-04-18
CVE-2000-0271 [MEDIUM] CVE-2000-0271: read-passwd and other Lisp functions in Emacs 20 do not properly clear the history of recently typed read-passwd and other Lisp functions in Emacs 20 do not properly clear the history of recently typed keys, which allows an attacker to read unencrypted passwords.
nvd
CVE-2000-0270P4LOWCVSS 3.6v20.0v20.1+5 more2000-04-18
CVE-2000-0270 [LOW] CVE-2000-0270: The make-temp-name Lisp function in Emacs 20 creates temporary files with predictable names, which a The make-temp-name Lisp function in Emacs 20 creates temporary files with predictable names, which allows attackers to conduct a symlink attack.
nvd
CVE-2001-1301P4LOWCVSS 1.2v20.42001-08-07
CVE-2001-1301 [LOW] CVE-2001-1301: rcs2log, as used in Emacs 20.4, xemacs 21.1.10 and other versions before 21.4, and possibly other pa rcs2log, as used in Emacs 20.4, xemacs 21.1.10 and other versions before 21.4, and possibly other packages, allows local users to modify files of other users via a symlink attack on a temporary file.
nvd
CVE-2000-0269P4LOWCVSS 2.1v20.0v20.1+5 more2000-04-18
CVE-2000-0269 [LOW] CVE-2000-0269: Emacs 20 does not properly set permissions for a slave PTY device when starting a new subprocess, wh Emacs 20 does not properly set permissions for a slave PTY device when starting a new subprocess, which allows local users to read or modify communications between Emacs and the subprocess.
nvd
Gnu Emacs vulnerabilities | cvebase