Kovid Goyal
17 exploits
Active since Mar 2018
Kitty <0.47.0 compose_rectangles - Heap Buffer Over-Read/Write
CVSS 9.9
Kitty <0.47.0 Graphics Protocol Handler - Heap Buffer Overflow
CVSS 7.5
Calibre 6.9.0-7.14.0 - Unauthenticated RCE
CVSS 9.8
kitty < 0.41.0 - Unauthenticated Arbitrary Code Execution via Untrusted Document Link
CVSS 4.1
calibre < 9.2.0 - Remote Code Execution via Templite Template Injection
CVSS 7.8
calibre < 9.3.0 - Path Traversal and Remote Code Execution via extract_pictures Function
CVSS 8.8
calibre < 9.3.0 - Path Traversal and Arbitrary File Write via PDB Reader
CVSS 8.8
Calibre - Remote Code Execution via cPickle Deserialization in Bookmark Import
CVSS 7.8
kitty < 0.19.3 - Remote Code Execution via Graphics Protocol Error Message
CVSS 9.8
mechanize < 0.4.6 - Regular Expression Denial of Service
CVSS 7.5
kitty < 0.26.2 - Remote Code Execution via Desktop Notification Escape Sequence
CVSS 7.8
calibre <= 7.14.0 - Unauthenticated Path Traversal and Arbitrary File Read
CVSS 7.5
calibre < 7.15.0 - Reflected Cross-Site Scripting
CVSS 5.4
calibre <= 7.15.0 - Authenticated SQL Injection via Full-Text Search
CVSS 4.2
calibre < 8.14.0 - Arbitrary File Write and Remote Code Execution via FB2 Binary Asset Filename
calibre < 9.2.0 - Path Traversal and Remote Code Execution via CHM Reader
CVSS 8.6
calibre < 9.2.0 - Path Traversal and Arbitrary File Write via EPUB Conversion
CVSS 8.2