XEmacs is a text editor and development environment descended from GNU Emacs, with a narrow but persistent vulnerability footprint centered on the core application itself. The observed disclosures reflect general application-level issues rather than a specific structural pattern, making this a compact vendor profile best understood alongside current severity and exploitation counts shown in the live panel.
The number and severity of CVEs published that impact products developed by Xemacs over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-2688HIGH Multiple integer overflows in glyphs-eimage.c in XEmacs 21.4.22, when running on Windows, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via | Aug 5, 2009 | 10.0 | 33 | NO | NO |
rcs2log, as used in Emacs 20.4, xemacs 21.1.10 and other versions before 21.4, and possibly other packages, allows local users to modify files of other users via a symlink attack o | Aug 7, 2001 | 1.2 | 13 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xemacs.
Media articles that mention a CVE ID that affects a product developed by Xemacs — matched by CVE ID, not by vendor name.