<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T01:09:09.156989+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:11030</id>
    <title>ALSA-2025:11030 — Moderate: emacs security update</title>
    <updated>2026-10-04T01:09:09.311967+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: emacs, AlmaLinux:8: emacs-common, AlmaLinux:8: emacs-lucid, AlmaLinux:8: emacs-nox, AlmaLinux:8: emacs-terminal</p>
<p>GNU Emacs is a powerful, customizable, self-documenting text editor. It provides special code editing features, a scripting language (elisp), and the capability to read e-mail and news.</p>
<p>Security Fix(es):</p>
<p>* emacs: arbitrary code execution via Lisp macro expansion (CVE-2024-53920)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:11030"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-10771</id>
    <title>bdu:2024-10771</title>
    <updated>2026-10-04T01:09:09.312037+00:00</updated>
    <content>bdu:2024-10771</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-10771"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0524</id>
    <title>certfr-2025-avi-0524 — De multiples vulnérabilités ont été découvertes dans VMware Tanzu. Elles permettent à un attaquant de provoquer un prob…</title>
    <updated>2026-10-04T01:09:09.312055+00:00</updated>
    <content>certfr-2025-avi-0524</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0524"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2025-12004</id>
    <title>cnvd-2025-12004</title>
    <updated>2026-10-04T01:09:09.312071+00:00</updated>
    <content>cnvd-2025-12004</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2025-12004"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-373342</id>
    <title>EUVD-2026-373342</title>
    <updated>2026-10-04T01:09:09.312083+00:00</updated>
    <content>EUVD-2026-373342</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-373342"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-53920</id>
    <title>fkie_cve-2024-53920</title>
    <updated>2026-10-04T01:09:09.312093+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code.)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-53920"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8737-h7fg-9xgj</id>
    <title>GHSA-8737-h7fg-9xgj</title>
    <updated>2026-10-04T01:09:09.312115+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In elisp-mode.el in GNU Emacs through 30.0.92, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code.)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8737-h7fg-9xgj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-53920</id>
    <title>msrc_CVE-2024-53920 — In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion)…</title>
    <updated>2026-10-04T01:09:09.312131+00:00</updated>
    <content>msrc_CVE-2024-53920</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-53920"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-2760</id>
    <title>OESA-2025-2760 — emacs security update</title>
    <updated>2026-10-04T01:09:09.312151+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: emacs, openEuler:22.03-LTS-SP4: emacs, openEuler:24.03-LTS: emacs, openEuler:24.03-LTS-SP1: emacs, openEuler:24.03-LTS-SP2: emacs, openEuler:20.03-LTS-SP4: emacs</p>
<p>Emacs is the extensible, customizable, self-documenting real-time display editor. At its core is an interpreter for Emacs Lisp, a dialect of the Lisp programming language with extensions to support text editing. And it is an entire ecosystem of functionality beyond text editing, including a project planner, mail and news reader, debugger interface, calendar, and more.

Security Fix(es):</p>
<p>In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code.)(CVE-2024-53920)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-2760"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14591-1</id>
    <title>openSUSE-SU-2024:14591-1 — emacs-29.4-11.1 on GA media</title>
    <updated>2026-10-04T01:09:09.312184+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>emacs-29.4-11.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:14591-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:11487</id>
    <title>RHSA-2025:11487 — Red Hat Security Advisory: A Subscription Management tool for finding and reporting Red Hat product usage</title>
    <updated>2026-10-04T01:09:09.312199+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>emacs: arbitrary code execution via Lisp macro expansion krb5: Kerberos RC4-HMAC-MD5 Checksum Vulnerability Enabling Message Spoofing via MD5 Collisions glibc: static setuid binary dlopen may incorrectly search LD_LIBRARY_PATH glibc: Vector register overwrite bug in glibc linux-pam: Linux-pam directory Traversal libarchive: Buffer Overflow vulnerability in libarchive</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:11487"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-53920</id>
    <title>UBUNTU-CVE-2024-53920</title>
    <updated>2026-10-04T01:09:09.312222+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: emacs24, Ubuntu:16.04:LTS: xemacs21, Ubuntu:16.04:LTS: xemacs21-packages, Ubuntu:Pro:18.04:LTS: emacs25, Ubuntu:18.04:LTS: xemacs21, Ubuntu:18.04:LTS: xemacs21-packages, Ubuntu:Pro:20.04:LTS: emacs, Ubuntu:20.04:LTS: xemacs21, Ubuntu:20.04:LTS: xemacs21-packages, Ubuntu:22.04:LTS: xemacs21 and 9 more</p>
<p>In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code.)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-53920"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3558</id>
    <title>WID-SEC-W-2024-3558 — GNU Emacs und Red Hat Enterprise Linux: Schwachstelle ermöglicht Codeausführung</title>
    <updated>2026-10-04T01:09:09.312263+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in GNU Emacs und Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3558"/>
  </entry>
</feed>
