Show filters
33 Total Results
Displaying 11-20 of 33
Sort by:
Attacker Value
Unknown

CVE-2014-3424

Disclosure Date: May 08, 2014 (last updated October 05, 2023)
lisp/net/tramp-sh.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/tramp.##### temporary file.
0
Attacker Value
Unknown

CVE-2014-3422

Disclosure Date: May 08, 2014 (last updated October 05, 2023)
lisp/emacs-lisp/find-gc.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file under /tmp/esrc/.
0
Attacker Value
Unknown

CVE-2014-3423

Disclosure Date: May 08, 2014 (last updated October 05, 2023)
lisp/net/browse-url.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/Mosaic.##### temporary file.
0
Attacker Value
Unknown

CVE-2014-3421

Disclosure Date: May 08, 2014 (last updated October 05, 2023)
lisp/gnus/gnus-fun.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on the /tmp/gnus.face.ppm temporary file.
0
Attacker Value
Unknown

CVE-2012-3479

Disclosure Date: August 25, 2012 (last updated October 04, 2023)
lisp/files.el in Emacs 23.2, 23.3, 23.4, and 24.1 automatically executes eval forms in local-variable sections when the enable-local-variables option is set to :safe, which allows user-assisted remote attackers to execute arbitrary Emacs Lisp code via a crafted file.
0
Attacker Value
Unknown

CVE-2012-0035

Disclosure Date: January 19, 2012 (last updated October 04, 2023)
Untrusted search path vulnerability in EDE in CEDET before 1.0.1, as used in GNU Emacs before 23.4 and other products, allows local users to gain privileges via a crafted Lisp expression in a Project.ede file in the directory, or a parent directory, of an opened file.
0
Attacker Value
Unknown

CVE-2010-0825

Disclosure Date: April 05, 2010 (last updated October 04, 2023)
lib-src/movemail.c in movemail in emacs 22 and 23 allows local users to read, modify, or delete arbitrary mailbox files via a symlink attack, related to improper file-permission checks.
0
Attacker Value
Unknown

CVE-2009-2688

Disclosure Date: August 05, 2009 (last updated October 04, 2023)
Multiple integer overflows in glyphs-eimage.c in XEmacs 21.4.22, when running on Windows, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) the tiff_instantiate function processing a crafted TIFF file, (2) the png_instantiate function processing a crafted PNG file, and (3) the jpeg_instantiate function processing a crafted JPEG file, all which trigger a heap-based buffer overflow. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2008-4952

Disclosure Date: November 05, 2008 (last updated October 04, 2023)
emacs-jabber in emacs-jabber 0.7.91 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/*.log temporary file.
0
Attacker Value
Unknown

CVE-2008-4191

Disclosure Date: September 24, 2008 (last updated October 04, 2023)
extract-table.pl in Emacspeak 26 and 28 allows local users to overwrite arbitrary files via a symlink attack on the extract-table.csv temporary file.
0