Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-5795

25
FAUCET Score

CVE-2007-5795 describes a vulnerability in GNU Emacs versions prior to 22.2, specifically within the hack-local-variables function. When the enable-local-variables setting was configured to :safe, the function failed to adequately search for unsafe or risky variables, potentially allowing user-assisted attackers to bypass security restrictions. This could lead to the modification of critical program variables through a malicious file containing a Local variables declaration. The vulnerability carries a CVSS score of 6.3, indicating a medium severity. It requires local access (AV:L) and medium attack complexity (AC:M), with no authentication needed (Au:N). The primary impact is on integrity (I:C) and availability (A:C), with no confidentiality impact (C:N). There is no evidence of active exploitation in the wild, and it is not listed in the KEV catalog. While no Metasploit or Nuclei modules exist, an exploit (EDB-30736) for code execution in Emacs 22.1 is available on ExploitDB. Community discussion and media coverage for this CVE are minimal.

Impacted Technologies

VendorProductVersion(s)CPE
<= 22.1CPE matchmatch criteria
cpe:2.3:a:gnu:emacs:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.3MEDIUM

AV:L/AC:M/Au:N/C:N/I:C/A:C

Confidentiality Impact
NONE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
LOCAL
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
3.4
Impact Score
9.2
CvssVersion
2.0

Exploit Intelligence

EPSS Score
0.72%
Probability of exploitation in next 30 days
EPSS Percentile
50.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-30736 · Nov 2, 2007
This CVE's current EPSS score of 0.0072 is in the 85th percentile among its peer group of 1,595 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2007-5795Moderate

emacs insufficient safe mode checks

Nov 2, 2007

References

bugs.debian.org / cgi-bin/bugreport.cgi
bugs.gentoo.org / show_bug.cgi
cvs.savannah.gnu.org / viewvc/emacs/emacs/lisp/files.el
docs.info.apple.com / article.html
lists.apple.com / archives/security-announce/2008/Mar/msg00001.html
osvdb.org / 42060
secunia.com / advisories/27508
secunia.com / advisories/27627
secunia.com / advisories/27728
secunia.com / advisories/27984
secunia.com / advisories/29420
security.gentoo.org / glsa/glsa-200712-03.xml
exchange.xforce.ibmcloud.com / vulnerabilities/38263
redhat.com / archives/fedora-package-announce/2007-November/msg00524.html
mandriva.com / security/advisories
securityfocus.com / bid/26327
ubuntu.com / usn/usn-541-1
vupen.com / english/advisories/2007/3715
vupen.com / english/advisories/2008/0924/references