← Vulnerability feed

Vulnerability record · CVE-2012-0035 · published 19 January 2012

CVE-2012-0035: Eric m ludlam cedet vulnerability

EEric M Ludlam · Cedet

Untrusted search path vulnerability in EDE in CEDET before 1.0.1, as used in GNU Emacs before 23.4 and other products, allows local users to gain privileges via a crafted Lisp expression in a Project.ede file in the directory, or a parent directory, of an opened file.

9.3 CVSS 2.0 High EPSS 2.3% · top 17.4%
9.3CVSS 2.0 base score
2.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
26References
16 Jun 2026Last modified by NVD

Description

Untrusted search path vulnerability in EDE in CEDET before 1.0.1, as used in GNU Emacs before 23.4 and other products, allows local users to gain privileges via a crafted Lisp expression in a Project.ede file in the directory, or a parent directory, of an opened file.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.fedoraproject.org/pipermail/package-announce/2012-January/072285.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-January/072288.html
http://lists.gnu.org/archive/html/emacs-devel/2012-01/msg00387.html Patch
http://openwall.com/lists/oss-security/2012/01/10/2 Patch
http://openwall.com/lists/oss-security/2012/01/10/4
http://secunia.com/advisories/47311 Vendor Advisory
http://secunia.com/advisories/47515 Vendor Advisory
http://secunia.com/advisories/50801
http://sourceforge.net/mailarchive/message.php?msg_id=28649762
http://sourceforge.net/mailarchive/message.php?msg_id=28657612
http://www.mandriva.com/security/advisories?name=MDVSA-2013:076
http://www.ubuntu.com/usn/USN-1586-1
https://security.gentoo.org/glsa/201812-05
http://lists.fedoraproject.org/pipermail/package-announce/2012-January/072285.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-January/072288.html
http://lists.gnu.org/archive/html/emacs-devel/2012-01/msg00387.html Patch
http://openwall.com/lists/oss-security/2012/01/10/2 Patch
http://openwall.com/lists/oss-security/2012/01/10/4
http://secunia.com/advisories/47311 Vendor Advisory
http://secunia.com/advisories/47515 Vendor Advisory
http://secunia.com/advisories/50801
http://sourceforge.net/mailarchive/message.php?msg_id=28649762
http://sourceforge.net/mailarchive/message.php?msg_id=28657612
http://www.mandriva.com/security/advisories?name=MDVSA-2013:076
http://www.ubuntu.com/usn/USN-1586-1
https://security.gentoo.org/glsa/201812-05

Track CVE-2012-0035 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-6109Gnu emacs memory buffer overflow vulnerabilityStack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly have unspecified ot…EPSS 3.0%9.8CVE-2024-39331Gnu emacs code injection vulnerabilityIn Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-comm…EPSS 1.3%9.8CVE-2022-48337Gnu emacs os command injection vulnerabilityGNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses …EPSS 1.6%8.8CVE-2017-14482Gnu emacs vulnerabilityGNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data containing an x-dis…EPSS 4.0%7.8CVE-2024-53920Gnu emacs code injection vulnerabilityIn elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp sourc…EPSS 0.60%7.8CVE-2024-30202Gnu emacs code injection vulnerabilityIn Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.EPSS 1.1%7.8CVE-2023-2491Gnu emacs command injection vulnerabilityA flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el ca…EPSS 0.46%7.8CVE-2023-27986Gnu emacs code injection vulnerabilityemacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-q…EPSS 0.48%

Source: NIST National Vulnerability Database (record CVE-2012-0035), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.