Skip to main content

Vendor/product archive

gnu / emacs CVEs

Beta · best-effort

36 CVEs tagged to gnu / emacs4 Critical, 13 High, 11 Medium, 8 Low, 0 Unrated.

CVE-2008-2142

Published May 12, 2008

Emacs 21 and XEmacs automatically load and execute .flc (fast lock) files that are associated with other files that are edited within Emacs, which allows user-assisted attackers t…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1694

Published Apr 22, 2008

vcdiff in Emacs 20.7 to 22.1.50, when used with SCCS, allows local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6109

Published Dec 7, 2007

Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a large precisi…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-5795

Published Nov 2, 2007

The hack-local-variables function in Emacs before 22.2, when enable-local-variables is set to :safe, does not properly search lists of unsafe or risky variables, which might allow…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0100

Published Feb 7, 2005

Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1232

Published Dec 31, 2003

Emacs 21.2.1 does not prompt or warn the user before executing Lisp code in the local variables section of a text file, which allows user-assisted attackers to execute arbitrary c…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1301

Published Aug 7, 2001

rcs2log, as used in Emacs 20.4, xemacs 21.1.10 and other versions before 21.4, and possibly other packages, allows local users to modify files of other users via a symlink attack…

CVSS 1.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2000-0269

Published Apr 18, 2000

Emacs 20 does not properly set permissions for a slave PTY device when starting a new subprocess, which allows local users to read or modify communications between Emacs and the s…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2000-0270

Published Apr 18, 2000

The make-temp-name Lisp function in Emacs 20 creates temporary files with predictable names, which allows attackers to conduct a symlink attack.

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2000-0271

Published Apr 18, 2000

read-passwd and other Lisp functions in Emacs 20 do not properly clear the history of recently typed keys, which allows an attacker to read unencrypted passwords.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 26-36 of 36 CVEsPage 2 of 2