Calibre-ebook

Calibre

20 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.02%
  • Veröffentlicht 27.03.2026 13:53:22
  • Zuletzt bearbeitet 30.03.2026 20:46:25

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a path traversal vulnerability exists in Calibre' handling of images in Markdown and other similar text-based files allowing ...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 27.03.2026 13:52:06
  • Zuletzt bearbeitet 30.03.2026 20:48:24

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a Server-Side Request Forgery vulnerability in the background-image endpoint of calibre e-book reader's web view allows an at...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 13.03.2026 19:00:09
  • Zuletzt bearbeitet 18.03.2026 14:01:22

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to 9.5.0, a path traversal vulnerability in the RocketBook (.rb) input plugin (src/calibre/ebooks/rb/reader.py) allows an attacker to write arb...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 27.02.2026 19:46:07
  • Zuletzt bearbeitet 04.03.2026 16:39:05

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.4.0, the calibre Content Server's brute-force protection mechanism uses a ban key derived from both `remote_addr` and the `X-Forwa...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 27.02.2026 19:44:39
  • Zuletzt bearbeitet 04.03.2026 16:40:42

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.4.0, an HTTP Response Header Injection vulnerability in the calibre Content Server allows any authenticated user to inject arbitra...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 20.02.2026 02:16:53
  • Zuletzt bearbeitet 20.02.2026 16:45:18

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below are vulnerable to Path Traversal through PDB readers (both 132-byte and 202-byte header variants) that allow arbitrary file ...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 20.02.2026 02:16:52
  • Zuletzt bearbeitet 20.02.2026 16:53:32

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below contain a Path Traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions. On Windows...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 06.02.2026 20:14:35
  • Zuletzt bearbeitet 17.02.2026 21:18:56

calibre is an e-book manager. Prior to 9.2.0, a Server-Side Template Injection (SSTI) vulnerability in Calibre's Templite templating engine allows arbitrary code execution when a user converts an ebook using a malicious custom template file via the -...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 06.02.2026 20:10:29
  • Zuletzt bearbeitet 17.02.2026 21:27:17

calibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains a path traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions. On Windows (haven't tested on other OS's), this can lead to Remote C...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 06.02.2026 20:07:40
  • Zuletzt bearbeitet 17.02.2026 21:23:11

calibre is an e-book manager. In 9.1.0 and earlier, a path traversal vulnerability in Calibre's EPUB conversion allows a malicious EPUB file to corrupt arbitrary existing files writable by the Calibre process. During conversion, Calibre resolves Ciph...