Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown

CVE-2014-3424

Disclosure Date: May 08, 2014 (last updated October 05, 2023)
lisp/net/tramp-sh.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/tramp.##### temporary file.
0
Attacker Value
Unknown

CVE-2014-3422

Disclosure Date: May 08, 2014 (last updated October 05, 2023)
lisp/emacs-lisp/find-gc.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file under /tmp/esrc/.
0
Attacker Value
Unknown

CVE-2014-3423

Disclosure Date: May 08, 2014 (last updated October 05, 2023)
lisp/net/browse-url.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/Mosaic.##### temporary file.
0
Attacker Value
Unknown

CVE-2014-3421

Disclosure Date: May 08, 2014 (last updated October 05, 2023)
lisp/gnus/gnus-fun.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on the /tmp/gnus.face.ppm temporary file.
0
Attacker Value
Unknown

CVE-2012-0035

Disclosure Date: January 19, 2012 (last updated October 04, 2023)
Untrusted search path vulnerability in EDE in CEDET before 1.0.1, as used in GNU Emacs before 23.4 and other products, allows local users to gain privileges via a crafted Lisp expression in a Project.ede file in the directory, or a parent directory, of an opened file.
0
Attacker Value
Unknown

CVE-2008-2142

Disclosure Date: May 12, 2008 (last updated October 04, 2023)
Emacs 21 and XEmacs automatically load and execute .flc (fast lock) files that are associated with other files that are edited within Emacs, which allows user-assisted attackers to execute arbitrary code.
0
Attacker Value
Unknown

CVE-2008-1694

Disclosure Date: April 22, 2008 (last updated October 04, 2023)
vcdiff in Emacs 20.7 to 22.1.50, when used with SCCS, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
0
Attacker Value
Unknown

CVE-2005-0100

Disclosure Date: February 07, 2005 (last updated February 22, 2025)
Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.
0