Skip to main content

Vendor/product archive

gnu / emacs CVEs

Beta · best-effort

36 CVEs tagged to gnu / emacs4 Critical, 13 High, 11 Medium, 8 Low, 0 Unrated.

CVE-2026-6861

Published Apr 22, 2026

A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially crafted SVG (Scalable Vector Graphics) CSS (Cascading Style She…

CVSS 6.1 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2024-53920

Published Nov 27, 2024

In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-39331

Published Jun 23, 2024

In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Or…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-30202

Published Mar 25, 2024

In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27986

Published Mar 9, 2023

emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-quote characters. It is fixed i…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27985

Published Mar 9, 2023

emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack of compliance with the Desktop…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-48339

Published Feb 20, 2023

An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-istext-command function, the parameter file and parameter srcdi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-48338

Published Feb 20, 2023

An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. The ruby-find-library-file fun…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-48337

Published Feb 20, 2023

GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-1000383

Published Oct 31, 2017

GNU Emacs version 25.3.1 (and other versions most likely) ignores umask when creating a backup save file ("[ORIGINAL_FILENAME]~") resulting in files that may be world readable or…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14482

Published Sep 14, 2017

GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data containing an x-display XML element that specifie…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9483

Published Aug 28, 2017

Emacs 24.4 allows remote attackers to bypass security restrictions.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-3424

Published May 8, 2014

lisp/net/tramp-sh.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/tramp.##### temporary file.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-3423

Published May 8, 2014

lisp/net/browse-url.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/Mosaic.##### temporary file.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-3422

Published May 8, 2014

lisp/emacs-lisp/find-gc.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file under /tmp/esrc/.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-3421

Published May 8, 2014

lisp/gnus/gnus-fun.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on the /tmp/gnus.face.ppm temporary file.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-1103

Published Sep 25, 2012

emacs/notmuch-mua.el in Notmuch before 0.11.1, when using the Emacs interface, allows user-assisted remote attackers to read arbitrary files via crafted MML tags, which are not pr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3479

Published Aug 25, 2012

lisp/files.el in Emacs 23.2, 23.3, 23.4, and 24.1 automatically executes eval forms in local-variable sections when the enable-local-variables option is set to :safe, which allows…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0035

Published Jan 19, 2012

Untrusted search path vulnerability in EDE in CEDET before 1.0.1, as used in GNU Emacs before 23.4 and other products, allows local users to gain privileges via a crafted Lisp exp…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-0825

Published Apr 5, 2010

lib-src/movemail.c in movemail in emacs 22 and 23 allows local users to read, modify, or delete arbitrary mailbox files via a symlink attack, related to improper file-permission c…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 36 CVEsPage 1 of 2