Brown Bear Software maintains a small portfolio centered on calendar and scheduling applications such as Calcium and iCal, which despite their narrow scope hold prominence in specialized deployment contexts. The recurring vulnerability signal centers on input-handling weaknesses, particularly cross-site scripting flaws arising from improper neutralization during web page generation. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Brown Bear Software over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-1263MEDIUM ICAL.EXE in iCal 3.7 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request, possibly due to an invalid method name. | Dec 31, 2003 | 5.0 | 28 | NO | YES |
CVE-2008-2507MEDIUM Cross-site scripting (XSS) vulnerability in Calcium40.pl in Brown Bear Software Calcium 3.10 and 4.0.4 allows remote attackers to inject arbitrary web script or HTML via the Calend | May 29, 2008 | 4.3 | 22 | NO | YES |
CVE-2006-0924MEDIUM Cross-site scripting (XSS) vulnerability in Brown Bear iCal 3.10 allows remote attackers to inject arbitrary web script or HTML via the Calendar Text field when a new event is adde | Feb 28, 2006 | 4.3 | 14 | NO | NO |
CVE-2006-0889MEDIUM Cross-site scripting (XSS) vulnerability in Calcium 3.10.1 allows remote attackers to inject arbitrary web script or HTML via the EventText parameter. NOTE: the provenance of this | Feb 25, 2006 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Brown Bear Software.
Media articles that mention a CVE ID that affects a product developed by Brown Bear Software — matched by CVE ID, not by vendor name.