Simon Brown's vulnerability footprint centers on Pebble, a modestly represented task-management and project-tracking application, with the observed weakness classes centered on input validation and cross-site scripting vulnerabilities typical of web-facing applications. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Simon Brown over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-4022MEDIUM Pebble before 2.6.4 allows remote attackers to trigger loss of blog-entry viewability via a crafted comment. | Nov 8, 2012 | 6.4 | 21 | NO | NO |
CVE-2012-5170MEDIUM Open redirect vulnerability in Pebble before 2.6.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | Nov 4, 2012 | 5.8 | 20 | NO | NO |
CVE-2012-4023MEDIUM CRLF injection vulnerability in Pebble before 2.6.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors. | Nov 8, 2012 | 4.3 | 17 | NO | NO |
CVE-2009-0736MEDIUM Cross-site scripting (XSS) vulnerability in Pebble before 2.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Feb 25, 2009 | 4.3 | 14 | NO | NO |
CVE-2006-5168MEDIUM Cross-site scripting (XSS) vulnerability in the search functionality in Simon Brown Pebble 2.0.0 RC1 and RC2 allows remote attackers to inject arbitrary web script or HTML via the | Oct 10, 2006 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Simon Brown.
Media articles that mention a CVE ID that affects a product developed by Simon Brown — matched by CVE ID, not by vendor name.