Search CVE reports
11 – 20 of 35 results
emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack of compliance with the Desktop Entry Specification. It is fixed in 29.0.90
6 affected packages
xemacs21, xemacs21-packages, emacs, emacs24, emacs25, emacs23
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| xemacs21 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| xemacs21-packages | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| emacs | Not affected | Not affected | Not affected | Not in release |
| emacs24 | — | Not in release | Not in release | Not in release |
| emacs25 | — | Not in release | Not in release | Not affected |
| emacs23 | — | Not in release | Not in release | Not in release |
Some fixes available 4 of 27
An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-istext-command function, the parameter file and parameter srcdir come from external input, and parameters are not...
6 affected packages
xemacs21, xemacs21-packages, emacs, emacs23, emacs24, emacs25
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| xemacs21 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| xemacs21-packages | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| emacs | Not affected | Fixed | Fixed | Not in release |
| emacs23 | — | Not in release | Not in release | Not in release |
| emacs24 | — | Not in release | Not in release | Not in release |
| emacs25 | — | Not in release | Not in release | Fixed |
Some fixes available 1 of 24
An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. The ruby-find-library-file function is an interactive function, and bound to C-c...
6 affected packages
emacs, emacs23, emacs24, emacs25, xemacs21, xemacs21-packages
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| emacs | Not affected | Fixed | Not affected | Not in release |
| emacs23 | — | Not in release | Not in release | Not in release |
| emacs24 | — | Not in release | Not in release | Not in release |
| emacs25 | — | Not in release | Not in release | Not affected |
| xemacs21 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| xemacs21-packages | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Some fixes available 4 of 27
GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the etags program. For...
6 affected packages
emacs, xemacs21, emacs24, emacs25, xemacs21-packages, emacs23
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| emacs | Not affected | Fixed | Fixed | Not in release |
| xemacs21 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| emacs24 | — | Not in release | Not in release | Not in release |
| emacs25 | — | Not in release | Not in release | Fixed |
| xemacs21-packages | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| emacs23 | — | Not in release | Not in release | Not in release |
Some fixes available 4 of 27
GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the ctags program. For...
6 affected packages
emacs, xemacs21-packages, emacs23, emacs24, emacs25, xemacs21
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| emacs | Not affected | Fixed | Fixed | Not in release |
| xemacs21-packages | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| emacs23 | — | Not in release | Not in release | Not in release |
| emacs24 | — | Not in release | Not in release | Not in release |
| emacs25 | — | Not in release | Not in release | Fixed |
| xemacs21 | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
GNU Emacs version 25.3.1 (and other versions most likely) ignores umask when creating a backup save file ("[ORIGINAL_FILENAME]~") resulting in files that may be world readable or otherwise accessible in ways not intended by the...
3 affected packages
emacs23, emacs24, emacs25
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| emacs23 | — | — | — | Not in release |
| emacs24 | — | — | — | Not in release |
| emacs25 | — | — | — | Ignored |
Some fixes available 3 of 4
GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data containing an x-display XML element that specifies execution of shell commands, related to an unsafe...
3 affected packages
emacs24, emacs25, emacs23
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| emacs24 | — | — | — | Not in release |
| emacs25 | — | — | — | Not affected |
| emacs23 | — | — | — | Not in release |
Emacs 24.4 allows remote attackers to bypass security restrictions.
3 affected packages
emacs23, emacs24, emacs25
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| emacs23 | — | — | — | Not in release |
| emacs24 | — | — | — | Not in release |
| emacs25 | — | — | — | Not affected |
lisp/net/tramp-sh.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/tramp.##### temporary file.
7 affected packages
emacs-snapshot, emacs22, emacs23, emacs24, emacs25...
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| emacs-snapshot | — | — | — | Not in release |
| emacs22 | — | — | — | Not in release |
| emacs23 | — | — | — | Not in release |
| emacs24 | — | — | — | Not in release |
| emacs25 | — | — | — | Not affected |
| xemacs21 | — | — | — | Not affected |
| xemacs21-packages | — | — | — | Not affected |
lisp/net/browse-url.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/Mosaic.##### temporary file.
7 affected packages
emacs22, emacs-snapshot, emacs23, emacs24, emacs25...
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| emacs22 | — | — | — | Not in release |
| emacs-snapshot | — | — | — | Not in release |
| emacs23 | — | — | — | Not in release |
| emacs24 | — | — | — | Not in release |
| emacs25 | — | — | — | Not affected |
| xemacs21 | — | — | — | Not affected |
| xemacs21-packages | — | — | — | Not affected |