cpe:/a:calibre-ebook:calibre:3.18.0 CVE-2018-7889 2018-03-08T16:29:00.207-05:00 2018-10-12T14:21:43.757-04:00 6.8 NETWORK MEDIUM NONE PARTIAL PARTIAL PARTIAL http://nvd.nist.gov 2018-10-09T11:19:46.237-04:00 CONFIRM https://bugs.launchpad.net/calibre/+bug/1753870 CONFIRM https://github.com/kovidgoyal/calibre/commit/aeb5b036a0bf657951756688b3c72bd68b6e4a7d gui2/viewer/bookmarkmanager.py in Calibre 3.18 calls cPickle.load on imported bookmark data, which allows remote attackers to execute arbitrary code via a crafted .pickle file, as demonstrated by Python code that contains an os.system call.