The mobiparseindex_entry function in index.c in Libmobi 0.3 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted mobi file.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-11725.json"