GNU / Emacs
35 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-96269 | emacs: GNU Emacs: Arbitrary code execution upon opening a file | HIGH | 7.5 | Sep 22, 2026 |
| CVE-2026-77219 | GNU Emacs < 31.0.91 Heap Over-Read via PBM/PPM/PGM Image Loader | MEDIUM | 6.9 | Aug 21, 2026 |
| CVE-2026-71394 | Heap Use of Uninitialized Memory in GNU Emacs for Android | MEDIUM | 5.3 | Aug 10, 2026 |
| CVE-2026-71393 | Heap Buffer Overflow in GNU Emacs for Android | MEDIUM | 5.3 | Aug 10, 2026 |
| CVE-2026-71392 | Integer Overflow in GNU Emacs for Android | MEDIUM | 5.3 | Aug 10, 2026 |
| CVE-2026-71391 | Off-by-One Error in GNU Emacs for Android | MEDIUM | 5.3 | Aug 10, 2026 |
| CVE-2026-6861 | Emacs: emacs: memory corruption vulnerability when processing svg css | HIGH | 7.1 | Apr 22, 2026 |
| CVE-2024-53920 | emacs: arbitrary code execution via Lisp macro expansion | HIGH | 7.8 | Nov 27, 2024 |
| CVE-2024-39331 | emacs: org-link-expand-abbrev: Do not evaluate arbitrary unsafe Elisp code | CRITICAL | 9.8 | Jun 23, 2024 |
| CVE-2024-30205 | emacs: Org mode considers contents of remote files to be trusted | HIGH | 7.8 | Mar 25, 2024 |
| CVE-2024-30204 | emacs: LaTeX preview is enabled by default for e-mail attachments | MEDIUM | 5.5 | Mar 25, 2024 |
| CVE-2024-30203 | emacs: Gnus treats inline MIME contents as trusted | MEDIUM | 5.5 | Mar 25, 2024 |
| CVE-2024-30202 | emacs: arbitrary Lisp code is evaluated as part of turning on Org mode | HIGH | 7.8 | Mar 25, 2024 |
| CVE-2023-2491 | emacs: Regression of CVE-2023-28617 fixes in the Red Hat Enterprise Linux | HIGH | 7.8 | May 17, 2023 |
| CVE-2023-27986 | emacs: Emacs Lisp code injection via a crafted mailto URI | HIGH | 7.8 | Mar 9, 2023 |
| CVE-2023-27985 | emacs: Shell command injection via a crafted mailto URI | HIGH | 7.8 | Mar 9, 2023 |
| CVE-2022-48339 | emacs: command injection vulnerability in htmlfontify.el | HIGH | 7.8 | Feb 20, 2023 |
| CVE-2022-48338 | emacs: local command injection in ruby-mode.el | HIGH | 7.3 | Feb 20, 2023 |
| CVE-2022-48337 | emacs: command execution via shell metacharacters | CRITICAL | 9.8 | Feb 20, 2023 |
| CVE-2022-45939 | emacs: ctags local command execution vulnerability | HIGH | 7.8 | Nov 28, 2022 |
| CVE-2017-1000383 | emacs: Ignores umask when creating a swap file | MEDIUM | 5.5 | Oct 31, 2017 |
| CVE-2017-14482 | emacs: command injection flaw within "enriched mode" handling | HIGH | 8.8 | Sep 14, 2017 |
| CVE-2014-9483 | Emacs 24.4 allows remote attackers to bypass security restrictions. | HIGH | 7.5 | Aug 28, 2017 |
| CVE-2014-3424 | emacs: multiple temporary file issues | LOW | 3.3 | May 8, 2014 |
| CVE-2014-3423 | emacs: multiple temporary file issues | LOW | 3.3 | May 8, 2014 |
Showing 1 to 25 of 35 CVEs