Debian Calibre vulnerabilities
23 known vulnerabilities affecting debian/calibre.
Total CVEs
23
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL8HIGH8MEDIUM5LOW2
Vulnerabilities
Page 2 of 2
CVE-2016-10187P4LOWCVSS 5.5fixed in calibre 2.75.1+dfsg-1 (bookworm)2016
CVE-2016-10187 [MEDIUM] CVE-2016-10187: calibre - The E-book viewer in calibre before 2.75 allows remote attackers to read arbitra...
The E-book viewer in calibre before 2.75 allows remote attackers to read arbitrary files via a crafted epub file with JavaScript.
Scope: local
bookworm: resolved (fixed in 2.75.1+dfsg-1)
bullseye: resolved (fixed in 2.75.1+dfsg-1)
forky: resolved (fixed in 2.75.1+dfsg-1)
sid: resolved (fixed in 2.75.1+dfsg-1)
trixie: resolved (fixed in 2.75.1+dfsg-1)
debian
CVE-2026-27824P4MEDIUMCVSS 5.3fixed in calibre 9.4.0+ds+~0.10.5-1 (forky)2026
CVE-2026-27824 [MEDIUM] CVE-2026-27824: calibre - calibre is a cross-platform e-book manager for viewing, converting, editing, and...
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.4.0, the calibre Content Server's brute-force protection mechanism uses a ban key derived from both `remote_addr` and the `X-Forwarded-For` header. Since the `X-Forwarded-For` header is read directly from the HTTP request without any validation o
debian
CVE-2026-33205P4MEDIUMCVSS 4.8fixed in calibre 9.6.0+ds+~0.10.5-1 (forky)2026
CVE-2026-33205 [MEDIUM] CVE-2026-33205: calibre - calibre is a cross-platform e-book manager for viewing, converting, editing, and...
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a Server-Side Request Forgery vulnerability in the background-image endpoint of calibre e-book reader's web view allows an attacker to perform blind GET requests to arbitrary URLs and exfiltrate information out from the ebook sandbox. Versio
debian
← Previous2 / 2