CVE-2012-0035: Eric M Ludlam Cedet
High severity, CVSS 9.3. EPSS: 2.3% chance of exploitation in the next 30 days.
Untrusted search path vulnerability in EDE in CEDET before 1.0.1, as used in GNU Emacs before 23.4 and other products, allows local users to gain privileges via a crafted Lisp expression in a Project.ede file in the directory, or a parent directory, of an opened file.
Affected products
- Eric M Ludlam Cedet: up to and including 1.0; version 1.0 only
- GNU Emacs: up to and including 23.3; version 20.0 only; version 20.1 only; version 20.2 only; version 20.3 only; version 20.4 only; …
Published 2012-01-19. Last modified 2026-06-16.