VendorsGNUxemacsall versions
Vulnerabilities

GNU XEmacs

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2001-0191
gnuserv before 3.12, as shipped with XEmacs, does not properly check the specified length of an X Windows MIT-MAGIC-COOKIE cookie, which allows remote attackers to execute arbitrary commands via a buffer overflow, or brute force authentication by using a short cookie length.
Published 2001-05-07 · Modified
10.0EPSS 0.055
CVE-2005-0100
Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.
Published 2005-02-08 · Modified
7.5EPSS 0.043
CVE-2008-2142
Emacs 21 and XEmacs automatically load and execute .flc (fast lock) files that are associated with other files that are edited within Emacs, which allows user-assisted attackers to execute arbitrary code.
Published 2008-05-12 · Modified
6.8EPSS 0.037