GNU
GNU Emacs: vulnerabilidades y CVE
GNU Emacs tiene 44 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE44
Últimos 12 meses9
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-96442 | Alta (7.8) | 0.17% | — | 23 sept 2026 | A code execution flaw was found in Emacs, affecting versions prior to 31.2. The Flymake mode using language backends other than Lisp would execute arbitrary code from the edited file while performing syntax checking.… |
| CVE-2026-96269 | Alta (7.5) | 0.15% | — | 22 sept 2026 | GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a file, because an untrusted value of read-symbol-shorthands affects the intern and unintern functions. This affects the default configuration; no… |
| CVE-2026-79992 | Alta (7.8) | 0.14% | — | 25 ago 2026 | A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which… |
| CVE-2026-77219 | Media (6.9) | 0.13% | — | 21 ago 2026 | GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to leak heap memory contents by supplying a crafted image with large dimensions and an elevated max color… |
| CVE-2026-71394 | Media (5.3) | 0.45% | — | 10 ago 2026 | GNU Emacs for Android improperly validates the table header input in sfnt_read_table_directory() in src/sfnt.c. Due to an incorrect comparison variable in the read-length check, a crafted font file that claims to… |
| CVE-2026-71393 | Media (5.3) | 0.67% | — | 10 ago 2026 | GNU Emacs for Android is vulnerable to an integer overflow in sfnt_read_name_table() in src/sfnt.c. The function computes an allocation size using a 32-bit length value from a TrueType font file without overflow… |
| CVE-2026-71392 | Media (5.3) | 0.67% | — | 10 ago 2026 | GNU Emacs for Android is vulnerable to an integer overflow in the sfnt_read_cmap_format_12() function in src/sfnt.c. When processing a crafted TrueType font file, an unguarded addition in the xmalloc allocation call… |
| CVE-2026-71391 | Media (5.3) | 0.54% | — | 10 ago 2026 | GNU Emacs for Android contains an off-by-one error in the gvar table parser in src/sfnt.c. The shared-coordinate index boundary check in sfnt_vary_simple_glyph() and sfnt_vary_compound_glyph() uses a strict greater-than… |
| CVE-2026-6861 | Alta (7.1) | 0.15% | — | 22 abr 2026 | A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially crafted SVG (Scalable Vector Graphics) CSS (Cascading Style Sheets) data. A local user could exploit… |
| CVE-2025-1244 | Alta (8.8) | 2.6% | — | 12 feb 2025 | A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arbitrary shell commands on a vulnerable system. Exploitation is possible by tricking users into… |
| CVE-2024-53920 | Alta (7.8) | 0.60% | — | 27 nov 2024 | In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers… |
| CVE-2024-39331 | Crítica (9.8) | 1.3% | — | 23 jun 2024 | In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org Mode before 9.7.5. |
| CVE-2024-30205 | Alta (7.1) | 0.48% | — | 25 mar 2024 | In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23. |
| CVE-2024-30204 | Baja (2.8) | 0.47% | — | 25 mar 2024 | In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments. |
| CVE-2024-30203 | Media (5.5) | 0.58% | — | 25 mar 2024 | In Emacs before 29.3, Gnus treats inline MIME contents as trusted. |
| CVE-2024-30202 | Alta (7.8) | 1.1% | — | 25 mar 2024 | In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23. |
| CVE-2023-2491 | Alta (7.8) | 0.46% | — | 17 may 2023 | A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el can result in arbitrary command execution. This CVE exists because of a… |
| CVE-2023-27986 | Alta (7.8) | 0.48% | — | 9 mar 2023 | emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-quote characters. It is fixed in 29.0.90. |
| CVE-2023-27985 | Alta (7.8) | 1.1% | — | 9 mar 2023 | emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack of compliance with the Desktop Entry Specification. It is fixed in… |
| CVE-2022-48339 | Alta (7.8) | 1.1% | — | 20 feb 2023 | An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-istext-command function, the parameter file and parameter srcdir come from external input, and… |
| CVE-2022-48338 | Alta (7.3) | 1.6% | — | 20 feb 2023 | An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. The ruby-find-library-file function is an interactive function, and… |
| CVE-2022-48337 | Crítica (9.8) | 1.6% | — | 20 feb 2023 | GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the etags… |
| CVE-2022-45939 | Alta (7.8) | 0.66% | — | 28 nov 2022 | GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the ctags… |
| CVE-2017-1000383 | Media (5.5) | 0.42% | — | 31 oct 2017 | GNU Emacs version 25.3.1 (and other versions most likely) ignores umask when creating a backup save file ("[ORIGINAL_FILENAME]~") resulting in files that may be world readable or otherwise accessible in ways not… |
| CVE-2017-14482 | Alta (8.8) | 4.0% | — | 14 sept 2017 | GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data containing an x-display XML element that specifies execution of shell commands, related… |
| CVE-2014-9483 | Alta (7.5) | 2.9% | — | 28 ago 2017 | Emacs 24.4 allows remote attackers to bypass security restrictions. |
| CVE-2014-3424 | Baja (3.3) | 0.34% | — | 8 may 2014 | lisp/net/tramp-sh.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/tramp.##### temporary file. |
| CVE-2014-3423 | Baja (3.3) | 0.34% | — | 8 may 2014 | lisp/net/browse-url.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/Mosaic.##### temporary file. |
| CVE-2014-3422 | Baja (3.3) | 0.34% | — | 8 may 2014 | lisp/emacs-lisp/find-gc.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file under /tmp/esrc/. |
| CVE-2014-3421 | Baja (3.3) | 0.34% | — | 8 may 2014 | lisp/gnus/gnus-fun.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on the /tmp/gnus.face.ppm temporary file. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.