Gnu

Emacs

41 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 3.66%
  • Veröffentlicht 12.05.2008 19:20:00
  • Zuletzt bearbeitet 16.06.2026 22:53:10

Emacs 21 and XEmacs automatically load and execute .flc (fast lock) files that are associated with other files that are edited within Emacs, which allows user-assisted attackers to execute arbitrary code.

  • EPSS 0.4%
  • Veröffentlicht 22.04.2008 04:41:00
  • Zuletzt bearbeitet 16.06.2026 22:52:17

vcdiff in Emacs 20.7 to 22.1.50, when used with SCCS, allows local users to overwrite arbitrary files via a symlink attack on temporary files.

  • EPSS 3.05%
  • Veröffentlicht 07.12.2007 11:46:00
  • Zuletzt bearbeitet 16.06.2026 22:47:25

Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a large precision value in an integer format string specifier to the format function, ...

  • EPSS 0.72%
  • Veröffentlicht 02.11.2007 22:46:00
  • Zuletzt bearbeitet 16.06.2026 22:46:50

The hack-local-variables function in Emacs before 22.2, when enable-local-variables is set to :safe, does not properly search lists of unsafe or risky variables, which might allow user-assisted attackers to bypass intended restrictions and modify cri...

  • EPSS 1.96%
  • Veröffentlicht 21.06.2007 20:30:00
  • Zuletzt bearbeitet 16.06.2026 22:40:31

Emacs 21 allows user-assisted attackers to cause a denial of service (crash) via certain crafted images, as demonstrated via a GIF image in vm mode, related to image size calculation.

  • EPSS 4.36%
  • Veröffentlicht 07.02.2005 05:00:00
  • Zuletzt bearbeitet 16.06.2026 22:10:30

Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.

  • EPSS 3.01%
  • Veröffentlicht 31.12.2003 05:00:00
  • Zuletzt bearbeitet 16.06.2026 22:03:45

Emacs 21.2.1 does not prompt or warn the user before executing Lisp code in the local variables section of a text file, which allows user-assisted attackers to execute arbitrary commands, as demonstrated using the mode-name variable.

  • EPSS 0.3%
  • Veröffentlicht 07.08.2001 04:00:00
  • Zuletzt bearbeitet 16.06.2026 21:55:59

rcs2log, as used in Emacs 20.4, xemacs 21.1.10 and other versions before 21.4, and possibly other packages, allows local users to modify files of other users via a symlink attack on a temporary file.

  • EPSS 0.36%
  • Veröffentlicht 18.04.2000 04:00:00
  • Zuletzt bearbeitet 16.06.2026 21:51:21

Emacs 20 does not properly set permissions for a slave PTY device when starting a new subprocess, which allows local users to read or modify communications between Emacs and the subprocess.

  • EPSS 0.34%
  • Veröffentlicht 18.04.2000 04:00:00
  • Zuletzt bearbeitet 16.06.2026 21:51:22

read-passwd and other Lisp functions in Emacs 20 do not properly clear the history of recently typed keys, which allows an attacker to read unencrypted passwords.