calibre
cpe:2.3:a:calibre-ebook:calibre:*:*:*:*:*:*:*
- <= 8.13.0
A vulnerability in Calibre's handling of binary assets in FB2 files prior to version 8.14.0 allows for arbitrary file writing on the filesystem. This issue can be exploited when viewing or converting a malicious FictionBook file, potentially leading to arbitrary code execution.
Exploitation of this vulnerability allows for arbitrary file writing, which can be leveraged to execute arbitrary code on the system.
Users can upgrade to Calibre version 8.14.0 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.