CVE-2024-30203
MEDIUMDescription
In Emacs before 29.3, Gnus treats inline MIME contents as trusted.
Is your site exposed to CVE-2024-30203?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| gnu | emacs |
| gnu | org_mode |
| debian | debian_linux |
References
Advisories & Patches
Other References
Frequently Asked Questions
What is CVE-2024-30203? +
How severe is CVE-2024-30203? +
What products are affected by CVE-2024-30203? +
How do I check if I'm vulnerable to CVE-2024-30203? +
Related Vulnerabilities
Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to …
In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such …
url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be …
An issue in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via the form_id in the …
GNU GRUB (aka GRUB2) through 2.12 has a heap-based buffer overflow in fs/hfs.c via crafted sblock data in an HFS …
OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via …