Show filters
33 Total Results
Displaying 21-30 of 33
Sort by:
Attacker Value
Unknown
CVE-2008-2142
Disclosure Date: May 12, 2008 (last updated October 04, 2023)
Emacs 21 and XEmacs automatically load and execute .flc (fast lock) files that are associated with other files that are edited within Emacs, which allows user-assisted attackers to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2008-1694
Disclosure Date: April 22, 2008 (last updated October 04, 2023)
vcdiff in Emacs 20.7 to 22.1.50, when used with SCCS, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
0
Attacker Value
Unknown
CVE-2007-6109
Disclosure Date: December 07, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a large precision value in an integer format string specifier to the format function, as demonstrated via a certain "emacs -batch -eval" command line.
0
Attacker Value
Unknown
CVE-2007-5795
Disclosure Date: November 02, 2007 (last updated October 04, 2023)
The hack-local-variables function in Emacs before 22.2, when enable-local-variables is set to :safe, does not properly search lists of unsafe or risky variables, which might allow user-assisted attackers to bypass intended restrictions and modify critical program variables via a file containing a Local variables declaration.
0
Attacker Value
Unknown
CVE-2007-2833
Disclosure Date: June 21, 2007 (last updated October 04, 2023)
Emacs 21 allows user-assisted attackers to cause a denial of service (crash) via certain crafted images, as demonstrated via a GIF image in vm mode, related to image size calculation.
0
Attacker Value
Unknown
CVE-2005-0100
Disclosure Date: February 07, 2005 (last updated February 22, 2025)
Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.
0
Attacker Value
Unknown
CVE-2003-1232
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Emacs 21.2.1 does not prompt or warn the user before executing Lisp code in the local variables section of a text file, which allows user-assisted attackers to execute arbitrary commands, as demonstrated using the mode-name variable.
0
Attacker Value
Unknown
CVE-2003-0537
Disclosure Date: August 18, 2003 (last updated February 22, 2025)
The liece Emacs IRC client 2.0+0.20030527 and earlier creates temporary files insecurely, which could allow local users to overwrite arbitrary files as other users.
0
Attacker Value
Unknown
CVE-2003-0539
Disclosure Date: August 18, 2003 (last updated February 22, 2025)
skk (Simple Kana to Kanji conversion program) 12.1 and earlier, and the ddskk package which is based on skk, creates temporary files insecurely, which allows local users to overwrite arbitrary files.
0
Attacker Value
Unknown
CVE-2001-1301
Disclosure Date: August 07, 2001 (last updated February 22, 2025)
rcs2log, as used in Emacs 20.4, xemacs 21.1.10 and other versions before 21.4, and possibly other packages, allows local users to modify files of other users via a symlink attack on a temporary file.
0