CVE-2026-96269
- EPSS 0.19%
- Veröffentlicht 22.09.2026 20:32:40
- Zuletzt bearbeitet 24.09.2026 21:00:46
GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a file, because an untrusted value of read-symbol-shorthands affects the intern and unintern functions. This affects the default configuration; no particular user settings are r...
CVE-2026-77219
- EPSS 0.13%
- Veröffentlicht 21.08.2026 21:17:06
- Zuletzt bearbeitet 24.09.2026 20:43:32
GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to leak heap memory contents by supplying a crafted image with large dimensions and an elevated max color index. The image loader multiplies...
CVE-2026-71394
- EPSS 0.28%
- Veröffentlicht 10.08.2026 10:23:11
- Zuletzt bearbeitet 28.08.2026 15:26:19
GNU Emacs for Android improperly validates the table header input in sfnt_read_table_directory() in src/sfnt.c. Due to an incorrect comparison variable in the read-length check, a crafted font file that claims to contain more table directory entries ...
CVE-2026-71393
- EPSS 0.39%
- Veröffentlicht 10.08.2026 10:22:37
- Zuletzt bearbeitet 28.08.2026 15:26:19
GNU Emacs for Android is vulnerable to an integer overflow in sfnt_read_name_table() in src/sfnt.c. The function computes an allocation size using a 32-bit length value from a TrueType font file without overflow checking. On 32-bit targets, a crafted...
CVE-2026-71392
- EPSS 0.39%
- Veröffentlicht 10.08.2026 10:22:26
- Zuletzt bearbeitet 28.08.2026 15:26:19
GNU Emacs for Android is vulnerable to an integer overflow in the sfnt_read_cmap_format_12() function in src/sfnt.c. When processing a crafted TrueType font file, an unguarded addition in the xmalloc allocation call wraps around on 32-bit builds, cau...
CVE-2026-71391
- EPSS 0.33%
- Veröffentlicht 10.08.2026 10:22:17
- Zuletzt bearbeitet 28.08.2026 15:26:19
GNU Emacs for Android contains an off-by-one error in the gvar table parser in src/sfnt.c. The shared-coordinate index boundary check in sfnt_vary_simple_glyph() and sfnt_vary_compound_glyph() uses a strict greater-than comparison instead of greater-...
CVE-2026-6861
- EPSS 0.11%
- Veröffentlicht 22.04.2026 14:17:07
- Zuletzt bearbeitet 06.05.2026 20:27:36
A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially crafted SVG (Scalable Vector Graphics) CSS (Cascading Style Sheets) data. A local user could exploit this by convincing a victim to op...
CVE-2024-53920
- EPSS 0.53%
- Veröffentlicht 27.11.2024 15:15:26
- Zuletzt bearbeitet 21.09.2026 22:16:54
In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This...
CVE-2024-39331
- EPSS 1.32%
- Veröffentlicht 23.06.2024 22:15:09
- Zuletzt bearbeitet 30.04.2025 16:44:51
In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org Mode before 9.7.5.
CVE-2024-30205
- EPSS 0.48%
- Veröffentlicht 25.03.2024 15:15:52
- Zuletzt bearbeitet 01.05.2025 14:32:31
In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.