threat
engine
.sh
Back
·
··:··
Home
/
Product
/
gnu emacs
Product
gnu emacs
36 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2026-6861
>= 28.1 and <= 30.2
A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially crafted SVG (S
6.1
MEDIUM
CVE-2024-53920
< 30.1
In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrust
7.8
HIGH
CVE-2024-39331
< 29.4
In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function,
9.8
CRITICAL
CVE-2024-30205
< 29.3
In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.
7.1
HIGH
CVE-2024-30204
< 29.3
In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.
2.8
LOW
CVE-2024-30203
< 29.3
In Emacs before 29.3, Gnus treats inline MIME contents as trusted.
5.5
MEDIUM
CVE-2024-30202
< 29.3
In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.
7.8
HIGH
CVE-2023-2491
all versions
A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" functio
7.8
HIGH
CVE-2023-27986
>= 28.1 and <= 28.2
emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with
7.8
HIGH
CVE-2023-27985
>= 28.1 and <= 28.2
emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This
7.8
HIGH
CVE-2022-48339
<= 28.2
An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-istext-command
7.8
HIGH
CVE-2022-48338
<= 28.2
An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command inject
7.3
HIGH
CVE-2022-48337
<= 28.2
GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because li
9.8
CRITICAL
CVE-2022-45939
<= 28.2
GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because li
7.8
HIGH
CVE-2017-1000383
<= 25.3.0
GNU Emacs version 25.3.1 (and other versions most likely) ignores umask when creating a backup save file ("[ORIGINAL_FILENAME]~")
5.5
MEDIUM
CVE-2017-14482
<= 25.2
GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data
8.8
HIGH
CVE-2014-9483
all versions
Emacs 24.4 allows remote attackers to bypass security restrictions.
7.5
HIGH
CVE-2014-3424
<= 24.3
lisp/net/tramp-sh.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/
CVE-2014-3423
<= 24.3
lisp/net/browse-url.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tm
CVE-2014-3422
<= 24.3
lisp/emacs-lisp/find-gc.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a
CVE-2014-3421
<= 24.3
lisp/gnus/gnus-fun.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on the /t
CVE-2012-3479
all versions
lisp/files.el in Emacs 23.2, 23.3, 23.4, and 24.1 automatically executes eval forms in local-variable sections when the enable-loc
CVE-2012-0035
<= 23.3
Untrusted search path vulnerability in EDE in CEDET before 1.0.1, as used in GNU Emacs before 23.4 and other products, allows loca
CVE-2010-0825
all versions
lib-src/movemail.c in movemail in emacs 22 and 23 allows local users to read, modify, or delete arbitrary mailbox files via a syml
CVE-2008-4952
all versions
emacs-jabber in emacs-jabber 0.7.91 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/*.log temporary
CVE-2008-2142
all versions
Emacs 21 and XEmacs automatically load and execute .flc (fast lock) files that are associated with other files that are edited wit
CVE-2008-1694
all versions
vcdiff in Emacs 20.7 to 22.1.50, when used with SCCS, allows local users to overwrite arbitrary files via a symlink attack on temp
CVE-2007-6109
all versions
Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly
CVE-2007-5795
<= 22.1
The hack-local-variables function in Emacs before 22.2, when enable-local-variables is set to :safe, does not properly search list
CVE-2007-2833
all versions
Emacs 21 allows user-assisted attackers to cause a denial of service (crash) via certain crafted images, as demonstrated via a GIF
CVE-2005-0100
<= 20.0
Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and
CVE-2003-1232
all versions
Emacs 21.2.1 does not prompt or warn the user before executing Lisp code in the local variables section of a text file, which allo
CVE-2001-1301
all versions
rcs2log, as used in Emacs 20.4, xemacs 21.1.10 and other versions before 21.4, and possibly other packages, allows local users to
CVE-2000-0271
all versions
read-passwd and other Lisp functions in Emacs 20 do not properly clear the history of recently typed keys, which allows an attacke
CVE-2000-0270
all versions
The make-temp-name Lisp function in Emacs 20 creates temporary files with predictable names, which allows attackers to conduct a s
CVE-2000-0269
all versions
Emacs 20 does not properly set permissions for a slave PTY device when starting a new subprocess, which allows local users to read
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin