Back

CVE-2005-0100

Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.

Published: Feb 7, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (3)

Vendor Product Version
gnu emacs *
gnu emacs 21.3
gnu xemacs *

GitHub Security Advisory GHSA-39qf-gxpw-7vqf

Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 4.36%

Top 10% most likely to be exploited

Threat Score 31.3 / 100

Data Sources

NVD EPSS GitHub