Vulnerabilities > GNU > Emacs > 19.9

DATE CVE VULNERABILITY TITLE RISK
2012-01-19 CVE-2012-0035 Untrusted search path vulnerability in EDE in CEDET before 1.0.1, as used in GNU Emacs before 23.4 and other products, allows local users to gain privileges via a crafted Lisp expression in a Project.ede file in the directory, or a parent directory, of an opened file.
network
eric-m-ludlam gnu
critical
9.3
2007-11-02 CVE-2007-5795 Local Variable Handling Code Execution vulnerability in GNU Emacs
The hack-local-variables function in Emacs before 22.2, when enable-local-variables is set to :safe, does not properly search lists of unsafe or risky variables, which might allow user-assisted attackers to bypass intended restrictions and modify critical program variables via a file containing a Local variables declaration.
local
debian gnu
6.3
2005-02-07 CVE-2005-0100 Remote Format String vulnerability in GNU Emacs and Xemacs
Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.
network
low complexity
gnu
7.5