cbcvebase.

Gnu Emacs vulnerabilities

41 known vulnerabilities affecting gnu/emacs.

Total CVEs
41
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH17MEDIUM13LOW8

Vulnerabilities

Page 2 of 3
CVE-2026-77219P4HIGHCVSS 7.1fixed in 31.0.912026-08-21
CVE-2026-77219 [HIGH] CWE-125 CVE-2026-77219: GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to leak heap memory contents by supplying a crafted image with large dimensions and an elevated max color index. The image loader multiplies image dimensions and channel count using signed integer arithmetic; for sufficiently large values, the
nvd
CVE-2026-71393P4MEDIUMCVSS 5.3≤ 30.22026-08-10
CVE-2026-71393 [MEDIUM] CWE-190 CVE-2026-71393: GNU Emacs for Android is vulnerable to an integer overflow in sfnt_read_name_table() in src/sfnt.c. GNU Emacs for Android is vulnerable to an integer overflow in sfnt_read_name_table() in src/sfnt.c. The function computes an allocation size using a 32-bit length value from a TrueType font file without overflow checking. On 32-bit targets, a crafted font causes the calculation to wrap, resulting in an undersized heap allocation. A subsequent read()
nvd
CVE-2026-71392P4MEDIUMCVSS 5.3≤ 30.22026-08-10
CVE-2026-71392 [MEDIUM] CWE-190 CVE-2026-71392: GNU Emacs for Android is vulnerable to an integer overflow in the sfnt_read_cmap_format_12() functio GNU Emacs for Android is vulnerable to an integer overflow in the sfnt_read_cmap_format_12() function in src/sfnt.c. When processing a crafted TrueType font file, an unguarded addition in the xmalloc allocation call wraps around on 32-bit builds, causing a heap buffer overflow write. An attacker can deliver a malicious font file via email, EWW (Emac
nvd
CVE-2026-71391P4MEDIUMCVSS 5.3≤ 30.22026-08-10
CVE-2026-71391 [MEDIUM] CWE-193 CVE-2026-71391: GNU Emacs for Android contains an off-by-one error in the gvar table parser in src/sfnt.c. The share GNU Emacs for Android contains an off-by-one error in the gvar table parser in src/sfnt.c. The shared-coordinate index boundary check in sfnt_vary_simple_glyph() and sfnt_vary_compound_glyph() uses a strict greater-than comparison instead of greater-than-or-equal, allowing a crafted TrueType variable font to bypass the check and trigger a heap-based
nvd
CVE-2026-71394P4MEDIUMCVSS 5.3≤ 30.22026-08-10
CVE-2026-71394 [MEDIUM] CWE-1284 CVE-2026-71394: GNU Emacs for Android improperly validates the table header input in sfnt_read_table_directory() in GNU Emacs for Android improperly validates the table header input in sfnt_read_table_directory() in src/sfnt.c. Due to an incorrect comparison variable in the read-length check, a crafted font file that claims to contain more table directory entries than actually present causes the parser to return a struct with uninitialized heap memory in the tabl
nvd
CVE-2026-6861P4HIGHCVSS 7.1≥ 28.1, ≤ 30.22026-04-22
CVE-2026-6861 [HIGH] CWE-193 CVE-2026-6861: A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs proc A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially crafted SVG (Scalable Vector Graphics) CSS (Cascading Style Sheets) data. A local user could exploit this by convincing a victim to open a malicious SVG file, which may lead to a denial of service (DoS) or potentially information disclosur
nvd
CVE-2024-30205P4HIGHCVSS 7.1fixed in 29.32024-03-25
CVE-2024-30205 [HIGH] CWE-494 CVE-2024-30205: In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mo In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.
nvdosv
CVE-2007-2833P4HIGHCVSS 7.8v212007-06-21
CVE-2007-2833 [HIGH] CVE-2007-2833: Emacs 21 allows user-assisted attackers to cause a denial of service (crash) via certain crafted ima Emacs 21 allows user-assisted attackers to cause a denial of service (crash) via certain crafted images, as demonstrated via a GIF image in vm mode, related to image size calculation.
nvd
CVE-2017-1000383P4MEDIUMCVSS 5.5≤ 25.3.02017-10-31
CVE-2017-1000383 [MEDIUM] CWE-200 CVE-2017-1000383: GNU Emacs version 25.3.1 (and other versions most likely) ignores umask when creating a backup save GNU Emacs version 25.3.1 (and other versions most likely) ignores umask when creating a backup save file ("[ORIGINAL_FILENAME]~") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the emacs binary.
nvd
CVE-2024-30203P4MEDIUMCVSS 5.5fixed in 29.32024-03-25
CVE-2024-30203 [MEDIUM] CVE-2024-30203: In Emacs before 29.3, Gnus treats inline MIME contents as trusted. In Emacs before 29.3, Gnus treats inline MIME contents as trusted.
nvdosv
CVE-2008-1694P4MEDIUMCVSS 4.6v20.7v21.1+3 more2008-04-22
CVE-2008-1694 [MEDIUM] CWE-59 CVE-2008-1694: vcdiff in Emacs 20.7 to 22.1.50, when used with SCCS, allows local users to overwrite arbitrary file vcdiff in Emacs 20.7 to 22.1.50, when used with SCCS, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
nvd
CVE-2010-0825P4MEDIUMCVSS 4.4v22.1v22.2+2 more2010-04-05
CVE-2010-0825 [MEDIUM] CWE-264 CVE-2010-0825: lib-src/movemail.c in movemail in emacs 22 and 23 allows local users to read, modify, or delete arbi lib-src/movemail.c in movemail in emacs 22 and 23 allows local users to read, modify, or delete arbitrary mailbox files via a symlink attack, related to improper file-permission checks.
nvd
CVE-2014-3422P4LOWCVSS 3.3≤ 24.3v20.0+23 more2014-05-08
CVE-2014-3422 [LOW] CWE-59 CVE-2014-3422: lisp/emacs-lisp/find-gc.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary f lisp/emacs-lisp/find-gc.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file under /tmp/esrc/.
nvd
CVE-2014-3421P4LOWCVSS 3.3≤ 24.3v20.0+23 more2014-05-08
CVE-2014-3421 [LOW] CWE-59 CVE-2014-3421: lisp/gnus/gnus-fun.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files lisp/gnus/gnus-fun.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on the /tmp/gnus.face.ppm temporary file.
nvd
CVE-2014-3424P4LOWCVSS 3.3≤ 24.3v20.0+23 more2014-05-08
CVE-2014-3424 [LOW] CWE-59 CVE-2014-3424: lisp/net/tramp-sh.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files v lisp/net/tramp-sh.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/tramp.##### temporary file.
nvd
CVE-2014-3423P4LOWCVSS 3.3≤ 24.3v20.0+23 more2014-05-08
CVE-2014-3423 [LOW] CWE-59 CVE-2014-3423: lisp/net/browse-url.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files lisp/net/browse-url.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/Mosaic.##### temporary file.
nvd
CVE-2024-30204P4LOWCVSS 2.8fixed in 29.32024-03-25
CVE-2024-30204 [LOW] CWE-276 CVE-2024-30204: In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments. In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.
nvdosv
CVE-2000-0271P4MEDIUMCVSS 4.6v20.0v20.1+5 more2000-04-18
CVE-2000-0271 [MEDIUM] CVE-2000-0271: read-passwd and other Lisp functions in Emacs 20 do not properly clear the history of recently typed read-passwd and other Lisp functions in Emacs 20 do not properly clear the history of recently typed keys, which allows an attacker to read unencrypted passwords.
nvd
CVE-2000-0270P4LOWCVSS 3.6v20.0v20.1+5 more2000-04-18
CVE-2000-0270 [LOW] CVE-2000-0270: The make-temp-name Lisp function in Emacs 20 creates temporary files with predictable names, which a The make-temp-name Lisp function in Emacs 20 creates temporary files with predictable names, which allows attackers to conduct a symlink attack.
nvd
CVE-2001-1301P4LOWCVSS 1.2v20.42001-08-07
CVE-2001-1301 [LOW] CVE-2001-1301: rcs2log, as used in Emacs 20.4, xemacs 21.1.10 and other versions before 21.4, and possibly other pa rcs2log, as used in Emacs 20.4, xemacs 21.1.10 and other versions before 21.4, and possibly other packages, allows local users to modify files of other users via a symlink attack on a temporary file.
nvd
Gnu Emacs vulnerabilities | cvebase