Home/Product/gnu emacs
Product

gnu emacs

36 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-6861
>= 28.1 and <= 30.2
A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially crafted SVG (S
6.1MEDIUM
CVE-2024-53920
< 30.1
In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrust
7.8HIGH
CVE-2024-39331
< 29.4
In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function,
9.8CRITICAL
CVE-2024-30205
< 29.3
In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.
7.1HIGH
CVE-2024-30204
< 29.3
In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.
2.8LOW
CVE-2024-30203
< 29.3
In Emacs before 29.3, Gnus treats inline MIME contents as trusted.
5.5MEDIUM
CVE-2024-30202
< 29.3
In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.
7.8HIGH
CVE-2023-2491
all versions
A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" functio
7.8HIGH
CVE-2023-27986
>= 28.1 and <= 28.2
emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with
7.8HIGH
CVE-2023-27985
>= 28.1 and <= 28.2
emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This
7.8HIGH
CVE-2022-48339
<= 28.2
An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-istext-command
7.8HIGH
CVE-2022-48338
<= 28.2
An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command inject
7.3HIGH
CVE-2022-48337
<= 28.2
GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because li
9.8CRITICAL
CVE-2022-45939
<= 28.2
GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because li
7.8HIGH
CVE-2017-1000383
<= 25.3.0
GNU Emacs version 25.3.1 (and other versions most likely) ignores umask when creating a backup save file ("[ORIGINAL_FILENAME]~")
5.5MEDIUM
CVE-2017-14482
<= 25.2
GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data
8.8HIGH
CVE-2014-9483
all versions
Emacs 24.4 allows remote attackers to bypass security restrictions.
7.5HIGH
CVE-2014-3424
<= 24.3
lisp/net/tramp-sh.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/
CVE-2014-3423
<= 24.3
lisp/net/browse-url.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tm
CVE-2014-3422
<= 24.3
lisp/emacs-lisp/find-gc.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a
CVE-2014-3421
<= 24.3
lisp/gnus/gnus-fun.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on the /t
CVE-2012-3479
all versions
lisp/files.el in Emacs 23.2, 23.3, 23.4, and 24.1 automatically executes eval forms in local-variable sections when the enable-loc
CVE-2012-0035
<= 23.3
Untrusted search path vulnerability in EDE in CEDET before 1.0.1, as used in GNU Emacs before 23.4 and other products, allows loca
CVE-2010-0825
all versions
lib-src/movemail.c in movemail in emacs 22 and 23 allows local users to read, modify, or delete arbitrary mailbox files via a syml
CVE-2008-4952
all versions
emacs-jabber in emacs-jabber 0.7.91 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/*.log temporary
CVE-2008-2142
all versions
Emacs 21 and XEmacs automatically load and execute .flc (fast lock) files that are associated with other files that are edited wit
CVE-2008-1694
all versions
vcdiff in Emacs 20.7 to 22.1.50, when used with SCCS, allows local users to overwrite arbitrary files via a symlink attack on temp
CVE-2007-6109
all versions
Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly
CVE-2007-5795
<= 22.1
The hack-local-variables function in Emacs before 22.2, when enable-local-variables is set to :safe, does not properly search list
CVE-2007-2833
all versions
Emacs 21 allows user-assisted attackers to cause a denial of service (crash) via certain crafted images, as demonstrated via a GIF
CVE-2005-0100
<= 20.0
Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and
CVE-2003-1232
all versions
Emacs 21.2.1 does not prompt or warn the user before executing Lisp code in the local variables section of a text file, which allo
CVE-2001-1301
all versions
rcs2log, as used in Emacs 20.4, xemacs 21.1.10 and other versions before 21.4, and possibly other packages, allows local users to
CVE-2000-0271
all versions
read-passwd and other Lisp functions in Emacs 20 do not properly clear the history of recently typed keys, which allows an attacke
CVE-2000-0270
all versions
The make-temp-name Lisp function in Emacs 20 creates temporary files with predictable names, which allows attackers to conduct a s
CVE-2000-0269
all versions
Emacs 20 does not properly set permissions for a slave PTY device when starting a new subprocess, which allows local users to read
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin