CVE-2024-30202
- EPSS 1.1%
- Veröffentlicht 25.03.2024 15:15:52
- Zuletzt bearbeitet 01.05.2025 14:33:59
In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.
CVE-2024-30203
- EPSS 0.58%
- Veröffentlicht 25.03.2024 15:15:52
- Zuletzt bearbeitet 01.05.2025 14:33:44
In Emacs before 29.3, Gnus treats inline MIME contents as trusted.
CVE-2024-30204
- EPSS 0.47%
- Veröffentlicht 25.03.2024 15:15:52
- Zuletzt bearbeitet 01.05.2025 14:33:32
In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.
CVE-2023-2491
- EPSS 0.46%
- Veröffentlicht 17.05.2023 22:15:10
- Zuletzt bearbeitet 22.01.2025 19:15:09
A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el can result in arbitrary command execution. This CVE exists because of a CVE-2023-28617 security regress...
CVE-2023-27986
- EPSS 0.48%
- Veröffentlicht 09.03.2023 06:15:33
- Zuletzt bearbeitet 05.03.2025 18:15:35
emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-quote characters. It is fixed in 29.0.90.
CVE-2023-27985
- EPSS 1.09%
- Veröffentlicht 09.03.2023 06:15:32
- Zuletzt bearbeitet 05.03.2025 17:15:12
emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack of compliance with the Desktop Entry Specification. It is fixed in 29.0.90
CVE-2022-48339
- EPSS 1.14%
- Veröffentlicht 20.02.2023 23:15:12
- Zuletzt bearbeitet 18.03.2025 16:15:15
An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-istext-command function, the parameter file and parameter srcdir come from external input, and parameters are not escaped. If a file n...
CVE-2022-48338
- EPSS 1.64%
- Veröffentlicht 20.02.2023 23:15:12
- Zuletzt bearbeitet 18.03.2025 16:15:14
An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. The ruby-find-library-file function is an interactive function, and bound to C-c C-f. Inside the func...
CVE-2022-48337
- EPSS 1.62%
- Veröffentlicht 20.02.2023 23:15:12
- Zuletzt bearbeitet 18.03.2025 16:15:14
GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the etags program. For example, a victim may u...
CVE-2022-45939
- EPSS 0.63%
- Veröffentlicht 28.11.2022 06:15:10
- Zuletzt bearbeitet 28.04.2025 19:15:46
GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the ctags program. For example, a victim may u...