Gnu

Emacs

41 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.42%
  • Veröffentlicht 31.10.2017 20:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

GNU Emacs version 25.3.1 (and other versions most likely) ignores umask when creating a backup save file ("[ORIGINAL_FILENAME]~") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the emacs...

  • EPSS 4.01%
  • Veröffentlicht 14.09.2017 16:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data containing an x-display XML element that specifies execution of shell commands, related to an unsafe text/enriched exten...

  • EPSS 2.85%
  • Veröffentlicht 28.08.2017 15:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Emacs 24.4 allows remote attackers to bypass security restrictions.

  • EPSS 0.34%
  • Veröffentlicht 08.05.2014 10:55:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

lisp/net/tramp-sh.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/tramp.##### temporary file.

  • EPSS 0.34%
  • Veröffentlicht 08.05.2014 10:55:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

lisp/net/browse-url.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/Mosaic.##### temporary file.

  • EPSS 0.34%
  • Veröffentlicht 08.05.2014 10:55:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

lisp/emacs-lisp/find-gc.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file under /tmp/esrc/.

  • EPSS 0.34%
  • Veröffentlicht 08.05.2014 10:55:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

lisp/gnus/gnus-fun.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on the /tmp/gnus.face.ppm temporary file.

  • EPSS 3.79%
  • Veröffentlicht 25.08.2012 10:29:51
  • Zuletzt bearbeitet 16.06.2026 23:43:18

lisp/files.el in Emacs 23.2, 23.3, 23.4, and 24.1 automatically executes eval forms in local-variable sections when the enable-local-variables option is set to :safe, which allows user-assisted remote attackers to execute arbitrary Emacs Lisp code vi...

  • EPSS 2.72%
  • Veröffentlicht 19.01.2012 15:55:00
  • Zuletzt bearbeitet 16.06.2026 23:36:32

Untrusted search path vulnerability in EDE in CEDET before 1.0.1, as used in GNU Emacs before 23.4 and other products, allows local users to gain privileges via a crafted Lisp expression in a Project.ede file in the directory, or a parent directory, ...

  • EPSS 0.33%
  • Veröffentlicht 05.04.2010 15:30:01
  • Zuletzt bearbeitet 16.06.2026 23:16:54

lib-src/movemail.c in movemail in emacs 22 and 23 allows local users to read, modify, or delete arbitrary mailbox files via a symlink attack, related to improper file-permission checks.