Vulnerabilities > Calibre Ebook > Calibre > 3.18.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-10-22 | CVE-2023-46303 | Server-Side Request Forgery (SSRF) vulnerability in Calibre-Ebook Calibre link_to_local_path in ebooks/conversion/plugins/html_input.py in calibre before 6.19.0 can, by default, add resources outside of the document root. | 7.5 |
2021-12-07 | CVE-2021-44686 | Resource Exhaustion vulnerability in multiple products calibre before 5.32.0 contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service) in html_preprocess_rules in ebooks/conversion/preprocess.py. | 7.5 |
2018-03-08 | CVE-2018-7889 | Deserialization of Untrusted Data vulnerability in Calibre-Ebook Calibre 3.18.0 gui2/viewer/bookmarkmanager.py in Calibre 3.18 calls cPickle.load on imported bookmark data, which allows remote attackers to execute arbitrary code via a crafted .pickle file, as demonstrated by Python code that contains an os.system call. | 6.8 |