Gnu

Emacs

41 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.1%
  • Veröffentlicht 25.03.2024 15:15:52
  • Zuletzt bearbeitet 01.05.2025 14:33:59

In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.

  • EPSS 0.58%
  • Veröffentlicht 25.03.2024 15:15:52
  • Zuletzt bearbeitet 01.05.2025 14:33:44

In Emacs before 29.3, Gnus treats inline MIME contents as trusted.

  • EPSS 0.47%
  • Veröffentlicht 25.03.2024 15:15:52
  • Zuletzt bearbeitet 01.05.2025 14:33:32

In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.

  • EPSS 0.46%
  • Veröffentlicht 17.05.2023 22:15:10
  • Zuletzt bearbeitet 22.01.2025 19:15:09

A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el can result in arbitrary command execution. This CVE exists because of a CVE-2023-28617 security regress...

  • EPSS 0.48%
  • Veröffentlicht 09.03.2023 06:15:33
  • Zuletzt bearbeitet 05.03.2025 18:15:35

emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-quote characters. It is fixed in 29.0.90.

  • EPSS 1.09%
  • Veröffentlicht 09.03.2023 06:15:32
  • Zuletzt bearbeitet 05.03.2025 17:15:12

emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack of compliance with the Desktop Entry Specification. It is fixed in 29.0.90

  • EPSS 1.14%
  • Veröffentlicht 20.02.2023 23:15:12
  • Zuletzt bearbeitet 18.03.2025 16:15:15

An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-istext-command function, the parameter file and parameter srcdir come from external input, and parameters are not escaped. If a file n...

  • EPSS 1.64%
  • Veröffentlicht 20.02.2023 23:15:12
  • Zuletzt bearbeitet 18.03.2025 16:15:14

An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. The ruby-find-library-file function is an interactive function, and bound to C-c C-f. Inside the func...

  • EPSS 1.62%
  • Veröffentlicht 20.02.2023 23:15:12
  • Zuletzt bearbeitet 18.03.2025 16:15:14

GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the etags program. For example, a victim may u...

  • EPSS 0.63%
  • Veröffentlicht 28.11.2022 06:15:10
  • Zuletzt bearbeitet 28.04.2025 19:15:46

GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the ctags program. For example, a victim may u...