VendorsGNUemacs23.3
Vulnerabilities

GNU Emacs 23.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2012-3479
lisp/files.el in Emacs 23.2, 23.3, 23.4, and 24.1 automatically executes eval forms in local-variable sections when the enable-local-variables option is set to :safe, which allows user-assisted remote attackers to execute arbitrary Emacs Lisp code via a crafted file.
Published 2012-08-25 · Modified
6.8EPSS 0.038
CVE-2014-3421
lisp/gnus/gnus-fun.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on the /tmp/gnus.face.ppm temporary file.
Published 2014-05-08 · Modified
3.3EPSS 0.003
CVE-2014-3422
lisp/emacs-lisp/find-gc.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file under /tmp/esrc/.
Published 2014-05-08 · Modified
3.3EPSS 0.003
CVE-2014-3424
lisp/net/tramp-sh.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/tramp.##### temporary file.
Published 2014-05-08 · Modified
3.3EPSS 0.003
CVE-2014-3423
lisp/net/browse-url.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/Mosaic.##### temporary file.
Published 2014-05-08 · Modified
3.3EPSS 0.003