9.3
CVSSv2

CVE-2012-0035

Published: 19/01/2012 Updated: 07/12/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Untrusted search path vulnerability in EDE in CEDET prior to 1.0.1, as used in GNU Emacs prior to 23.4 and other products, allows local users to gain privileges via a crafted Lisp expression in a Project.ede file in the directory, or a parent directory, of an opened file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

eric m ludlam cedet 1.0

gnu emacs 20.1

gnu emacs 20.2

gnu emacs 21.3

gnu emacs 22.1

gnu emacs 23.1

gnu emacs 23.2

gnu emacs 20.0

gnu emacs 21

gnu emacs 21.2.1

gnu emacs 22.2

gnu emacs 22.3

eric m ludlam cedet

gnu emacs 20.5

gnu emacs 20.6

gnu emacs 21.3.1

gnu emacs 21.4

gnu emacs 20.3

gnu emacs 20.4

gnu emacs 20.7

gnu emacs 21.1

gnu emacs 21.2

gnu emacs

gnu emacs 23.4

Vendor Advisories

Emacs could be made to run programs as your login if it opened a specially crafted file ...