Search CVE reports
21 – 30 of 36 results
Some fixes available 4 of 29
GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the etags program. For...
6 affected packages
emacs, xemacs21, xemacs21-packages, emacs23, emacs24, emacs25
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| emacs | Not affected | Not affected | Fixed | Fixed | Not in release |
| xemacs21 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| xemacs21-packages | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| emacs23 | — | — | Not in release | Not in release | Not in release |
| emacs24 | — | — | Not in release | Not in release | Not in release |
| emacs25 | — | — | Not in release | Not in release | Fixed |
Some fixes available 4 of 29
GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the ctags program. For...
6 affected packages
emacs, xemacs21, xemacs21-packages, emacs23, emacs24, emacs25
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| emacs | Not affected | Not affected | Fixed | Fixed | Not in release |
| xemacs21 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| xemacs21-packages | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| emacs23 | — | — | Not in release | Not in release | Not in release |
| emacs24 | — | — | Not in release | Not in release | Not in release |
| emacs25 | — | — | Not in release | Not in release | Fixed |
lisp/net/tramp-sh.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/tramp.##### temporary file.
7 affected packages
emacs-snapshot, emacs22, emacs23, emacs24, emacs25...
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| emacs-snapshot | — | — | — | — | Not in release |
| emacs22 | — | — | — | — | Not in release |
| emacs23 | — | — | — | — | Not in release |
| emacs24 | — | — | — | — | Not in release |
| emacs25 | — | — | — | — | Not affected |
| xemacs21 | — | — | — | — | Not affected |
| xemacs21-packages | — | — | — | — | Not affected |
lisp/net/browse-url.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/Mosaic.##### temporary file.
7 affected packages
emacs-snapshot, emacs22, emacs23, emacs24, emacs25...
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| emacs-snapshot | — | — | — | — | Not in release |
| emacs22 | — | — | — | — | Not in release |
| emacs23 | — | — | — | — | Not in release |
| emacs24 | — | — | — | — | Not in release |
| emacs25 | — | — | — | — | Not affected |
| xemacs21 | — | — | — | — | Not affected |
| xemacs21-packages | — | — | — | — | Not affected |
lisp/emacs-lisp/find-gc.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file under /tmp/esrc/.
7 affected packages
emacs-snapshot, emacs22, emacs23, emacs24, emacs25...
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| emacs-snapshot | — | — | — | — | Not in release |
| emacs22 | — | — | — | — | Not in release |
| emacs23 | — | — | — | — | Not in release |
| emacs24 | — | — | — | — | Not in release |
| emacs25 | — | — | — | — | Not affected |
| xemacs21 | — | — | — | — | Not affected |
| xemacs21-packages | — | — | — | — | Not affected |
lisp/gnus/gnus-fun.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on the /tmp/gnus.face.ppm temporary file.
7 affected packages
xemacs21-packages, emacs-snapshot, emacs22, emacs23, emacs24...
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| xemacs21-packages | Vulnerable | Vulnerable | Vulnerable | Vulnerable | Vulnerable |
| emacs-snapshot | Not in release | Not in release | Not in release | Not in release | Not in release |
| emacs22 | Not in release | Not in release | Not in release | Not in release | Not in release |
| emacs23 | Not in release | Not in release | Not in release | Not in release | Not in release |
| emacs24 | Not in release | Not in release | Not in release | Not in release | Not in release |
| emacs25 | Not in release | Not in release | Not in release | Not in release | Not affected |
| xemacs21 | Not affected | Not affected | Not affected | Not affected | Not affected |
Some fixes available 8 of 15
lisp/files.el in Emacs 23.2, 23.3, 23.4, and 24.1 automatically executes eval forms in local-variable sections when the enable-local-variables option is set to :safe, which allows user-assisted remote attackers to execute...
6 affected packages
emacs-snapshot, emacs21, emacs22, emacs23, emacs24, xemacs21
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| emacs-snapshot | — | — | — | — | — |
| emacs21 | — | — | — | — | — |
| emacs22 | — | — | — | — | — |
| emacs23 | — | — | — | — | — |
| emacs24 | — | — | — | — | — |
| xemacs21 | — | — | — | — | — |
Some fixes available 15 of 25
lib-src/movemail.c in movemail in emacs 22 and 23 allows local users to read, modify, or delete arbitrary mailbox files via a symlink attack, related to improper file-permission checks.
4 affected packages
emacs21, emacs22, emacs23, xemacs21
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| emacs21 | — | — | — | — | — |
| emacs22 | — | — | — | — | — |
| emacs23 | — | — | — | — | — |
| xemacs21 | — | — | — | — | — |
Multiple integer overflows in glyphs-eimage.c in XEmacs 21.4.22, when running on Windows, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) the tiff_instantiate function processing a...
1 affected package
xemacs21
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| xemacs21 | — | — | — | — | — |
emacs/lisp/progmodes/python.el in Emacs 22.1 and 22.2 imports Python script from the current working directory during editing of a Python file, which allows local users to execute arbitrary code via a Trojan horse Python file.
2 affected packages
emacs21, emacs22
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| emacs21 | — | — | — | — | — |
| emacs22 | — | — | — | — | — |