Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2014-3424

Disclosure Date: May 08, 2014 (last updated October 05, 2023)
lisp/net/tramp-sh.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/tramp.##### temporary file.
0
Attacker Value
Unknown

CVE-2014-3422

Disclosure Date: May 08, 2014 (last updated October 05, 2023)
lisp/emacs-lisp/find-gc.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file under /tmp/esrc/.
0
Attacker Value
Unknown

CVE-2014-3423

Disclosure Date: May 08, 2014 (last updated October 05, 2023)
lisp/net/browse-url.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/Mosaic.##### temporary file.
0
Attacker Value
Unknown

CVE-2014-3421

Disclosure Date: May 08, 2014 (last updated October 05, 2023)
lisp/gnus/gnus-fun.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on the /tmp/gnus.face.ppm temporary file.
0
Attacker Value
Unknown

CVE-2012-0035

Disclosure Date: January 19, 2012 (last updated October 04, 2023)
Untrusted search path vulnerability in EDE in CEDET before 1.0.1, as used in GNU Emacs before 23.4 and other products, allows local users to gain privileges via a crafted Lisp expression in a Project.ede file in the directory, or a parent directory, of an opened file.
0
Attacker Value
Unknown

CVE-2001-1301

Disclosure Date: August 07, 2001 (last updated February 22, 2025)
rcs2log, as used in Emacs 20.4, xemacs 21.1.10 and other versions before 21.4, and possibly other packages, allows local users to modify files of other users via a symlink attack on a temporary file.
0
Attacker Value
Unknown

CVE-2000-0270

Disclosure Date: April 18, 2000 (last updated February 22, 2025)
The make-temp-name Lisp function in Emacs 20 creates temporary files with predictable names, which allows attackers to conduct a symlink attack.
0
Attacker Value
Unknown

CVE-2000-0269

Disclosure Date: April 18, 2000 (last updated February 22, 2025)
Emacs 20 does not properly set permissions for a slave PTY device when starting a new subprocess, which allows local users to read or modify communications between Emacs and the subprocess.
0
Attacker Value
Unknown

CVE-2000-0271

Disclosure Date: April 18, 2000 (last updated February 22, 2025)
read-passwd and other Lisp functions in Emacs 20 do not properly clear the history of recently typed keys, which allows an attacker to read unencrypted passwords.
0