VendorsCalibre E-bookcalibre3.18.0
Vulnerabilities

Calibre E-book Calibre 3.18.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2018-7889
gui2/viewer/bookmarkmanager.py in Calibre 3.18 calls cPickle.load on imported bookmark data, which allows remote attackers to execute arbitrary code via a crafted .pickle file, as demonstrated by Python code that contains an os.system call.
Published 2018-03-08 · Modified
7.8EPSS 0.045