CVE-2012-0035
Last modified
CVE-2012-0035 is a vulnerability of currently unknown severity. Untrusted search path vulnerability in EDE in CEDET before 1.0.1, as used in GNU Emacs before 23.4 and other products, allows local users to gain privileges via a crafted Lisp expression in a Project.ede file in the directory, or a parent directory, of an opened file.. EPSS estimates a 2.73% chance of exploitation in the next 30 days.
Description
Untrusted search path vulnerability in EDE in CEDET before 1.0.1, as used in GNU Emacs before 23.4 and other products, allows local users to gain privileges via a crafted Lisp expression in a Project.ede file in the directory, or a parent directory, of an opened file.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Eric M Ludlam | Cedet | <= 1.0 | — |
| Eric M Ludlam | Cedet | 1.0 | Beta1 |
| Gnu | Emacs | <= 23.3 | — |
| Gnu | Emacs | 20.0 | — |
| Gnu | Emacs | 20.1 | — |
| Gnu | Emacs | 20.2 | — |
| Gnu | Emacs | 20.3 | — |
| Gnu | Emacs | 20.4 | — |
| Gnu | Emacs | 20.5 | — |
| Gnu | Emacs | 20.6 | — |
| Gnu | Emacs | 20.7 | — |
| Gnu | Emacs | 21 | — |
| Gnu | Emacs | 21.1 | — |
| Gnu | Emacs | 21.2 | — |
| Gnu | Emacs | 21.2.1 | — |
| Gnu | Emacs | 21.3 | — |
| Gnu | Emacs | 21.3.1 | — |
| Gnu | Emacs | 21.4 | — |
| Gnu | Emacs | 22.1 | — |
| Gnu | Emacs | 22.2 | — |
| Gnu | Emacs | 22.3 | — |
| Gnu | Emacs | 23.1 | — |
| Gnu | Emacs | 23.2 | — |
| Gnu | Emacs | 23.4 | — |
References
- http://secunia.com/advisories/47311Vendor Advisory
- http://secunia.com/advisories/47515Vendor Advisory
- http://secunia.com/advisories/47311Vendor Advisory
- http://secunia.com/advisories/47515Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-0035?
How severe is CVE-2012-0035?
How do I fix CVE-2012-0035?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-0029Heap-based buffer overflow in the process_tx_desc function i…
- CVE-2012-0030Nova 2011.3 and Essex, when using the OpenStack API, allows …
- CVE-2012-0031scoreboard.c in the Apache HTTP Server 2.2.21 and earlier mi…
- CVE-2012-0032Red Hat JBoss Operations Network (JON) before 3.0.1 uses 077…
- CVE-2012-0033The CBounceDCCMod::OnPrivCTCP function in bouncedcc.cpp in t…
- CVE-2012-0034The NonManagedConnectionFactory in JBoss Enterprise Applicat…
- CVE-2012-0036curl and libcurl 7.2x before 7.24.0 do not properly consider…
- CVE-2012-0037Redland Raptor (aka libraptor) before 2.0.7, as used by Open…6.5
- CVE-2012-0038Integer overflow in the xfs_acl_from_disk function in fs/xfs…5.5
- CVE-2012-0039GLib 2.31.8 and earlier, when the g_str_hash function is use…7.5
- CVE-2012-0040Cross-site scripting (XSS) vulnerability in modules/core/www…
- CVE-2012-0041The dissect_packet function in epan/packet.c in Wireshark 1.…
Are you affected by CVE-2012-0035?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
