Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

49 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.9%—GNU Emacs28/8/201717/6/2026
Emacs 24.4 allows remote attackers to bypass security restrictions.
ModificadaBaja (3.3)0.36%—Mageia Project MageiaGNU Emacs8/5/201417/6/2026
lisp/net/tramp-sh.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/tramp.##### temporary file.
ModificadaBaja (3.3)0.35%—Mageia Project MageiaGNU Emacs8/5/201417/6/2026
lisp/net/browse-url.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/Mosaic.##### temporary file.
ModificadaBaja (3.3)0.34%—GNU EmacsMageia Project Mageia8/5/201417/6/2026
lisp/emacs-lisp/find-gc.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file under /tmp/esrc/.
ModificadaBaja (3.3)0.34%—Mageia Project MageiaGNU Emacs8/5/201417/6/2026
lisp/gnus/gnus-fun.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on the /tmp/gnus.face.ppm temporary file.
ModificadaMedia (6.8)3.8%—GNU Emacs25/8/201216/6/2026
lisp/files.el in Emacs 23.2, 23.3, 23.4, and 24.1 automatically executes eval forms in local-variable sections when the enable-local-variables option is set to :safe, which allows user-assisted remote attackers to execute arbitrary Emacs Lisp code via a crafted file.
ModificadaAlta (9.3)2.3%—Eric M Ludlam CedetGNU Emacs19/1/201216/6/2026
Untrusted search path vulnerability in EDE in CEDET before 1.0.1, as used in GNU Emacs before 23.4 and other products, allows local users to gain privileges via a crafted Lisp expression in a Project.ede file in the directory, or a parent directory, of an opened file.
ModificadaMedia (4.4)0.32%—GNU Emacs5/4/201016/6/2026
lib-src/movemail.c in movemail in emacs 22 and 23 allows local users to read, modify, or delete arbitrary mailbox files via a symlink attack, related to improper file-permission checks.
ModificadaAlta (10)8.6%—Xemacs5/8/200916/6/2026
Multiple integer overflows in glyphs-eimage.c in XEmacs 21.4.22, when running on Windows, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) the tiff_instantiate function processing a crafted TIFF file, (2) the png_instantiate function processing a crafted PNG file, and (3)…
ModificadaMedia (6.9)0.37%—Emacs-jabber5/11/200816/6/2026
emacs-jabber in emacs-jabber 0.7.91 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/*.log temporary file.
ModificadaMedia (6.6)0.41%—Emacspeak INC Emacspeak24/9/200816/6/2026
extract-table.pl in Emacspeak 26 and 28 allows local users to overwrite arbitrary files via a symlink attack on the extract-table.csv temporary file.
ModificadaMedia (6.8)3.7%—GNU EmacsGNU Xemacs12/5/200816/6/2026
Emacs 21 and XEmacs automatically load and execute .flc (fast lock) files that are associated with other files that are edited within Emacs, which allows user-assisted attackers to execute arbitrary code.
ModificadaMedia (4.6)0.40%—GNU EmacsGNU Sccs22/4/200816/6/2026
vcdiff in Emacs 20.7 to 22.1.50, when used with SCCS, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
ModificadaAlta (10)3.0%—GNU Emacs7/12/200716/6/2026
Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a large precision value in an integer format string specifier to the format function, as demonstrated via a certain "emacs -batch -eval" command line.
ModificadaMedia (6.3)0.72%💥 ExploitGNU Emacs2/11/200716/6/2026
The hack-local-variables function in Emacs before 22.2, when enable-local-variables is set to :safe, does not properly search lists of unsafe or risky variables, which might allow user-assisted attackers to bypass intended restrictions and modify critical program variables via a file containing a Local variables…
ModificadaAlta (7.8)2.0%—Debian LinuxGNU Emacs21/6/200716/6/2026
Emacs 21 allows user-assisted attackers to cause a denial of service (crash) via certain crafted images, as demonstrated via a GIF image in vm mode, related to image size calculation.
ModificadaAlta (7.5)4.3%—GNU EmacsGNU Xemacs7/2/200516/6/2026
Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.
ModificadaMedia (5.1)3.0%💥 ExploitGNU Emacs31/12/200316/6/2026
Emacs 21.2.1 does not prompt or warn the user before executing Lisp code in the local variables section of a text file, which allows user-assisted attackers to execute arbitrary commands, as demonstrated using the mode-name variable.
ModificadaMedia (4.6)0.35%—Daiki Ueno Liece Emacs IRC Client18/8/200316/6/2026
The liece Emacs IRC client 2.0+0.20030527 and earlier creates temporary files insecurely, which could allow local users to overwrite arbitrary files as other users.
ModificadaMedia (4.6)0.36%—DdskkRedhat Daredevil SKKRedhat Ddskk-xemacsSKK18/8/200316/6/2026
skk (Simple Kana to Kanji conversion program) 12.1 and earlier, and the ddskk package which is based on skk, creates temporary files insecurely, which allows local users to overwrite arbitrary files.
ModificadaBaja (1.2)0.29%—GNU EmacsXemacs7/8/200116/6/2026
rcs2log, as used in Emacs 20.4, xemacs 21.1.10 and other versions before 21.4, and possibly other packages, allows local users to modify files of other users via a symlink attack on a temporary file.
ModificadaBaja (2.1)0.36%—GNU Emacs18/4/200016/6/2026
Emacs 20 does not properly set permissions for a slave PTY device when starting a new subprocess, which allows local users to read or modify communications between Emacs and the subprocess.
ModificadaBaja (3.6)0.35%—GNU Emacs18/4/200016/6/2026
The make-temp-name Lisp function in Emacs 20 creates temporary files with predictable names, which allows attackers to conduct a symlink attack.
ModificadaMedia (4.6)0.34%—GNU Emacs18/4/200016/6/2026
read-passwd and other Lisp functions in Emacs 20 do not properly clear the history of recently typed keys, which allows an attacker to read unencrypted passwords.
Orbitaley — Vulnerabilidades