Objective Development Software GmbH
Self-Reporting Analysis
Of all the CVEs published by Objective Development Software GmbH as a CNA, 83.3% affect products that Objective Development Software GmbH develops as a vendor.
Of all the CVEs published that affect products developed by Objective Development Software GmbH, 100.0% are self-published by Objective Development Software GmbH as a CNA.
Trends Over Time
The number and severity of CVEs published by Objective Development Software GmbH over time
Top CVEs
All CVEs published by Objective Development Software GmbH as a CNA, regardless of affected vendor or product.
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-13095HIGH Little Snitch version 4.5.1 and older changed ownership of a directory path controlled by the user. This allowed the user to escalate to root by linking the path to a directory con | Jun 30, 2020 | 8.8 | 28 | NO | NO |
CVE-2016-8661HIGH Little Snitch version 3.0 through 3.6.1 suffer from a buffer overflow vulnerability that could be locally exploited which could lead to an escalation of privileges (EoP) and unauth | Nov 15, 2016 | 8.4 | 27 | NO | NO |
CVE-2017-2675HIGH Little Snitch version 3.0 through 3.7.3 suffer from a local privilege escalation vulnerability in the installer part. The vulnerability is related to the installation of the config | Apr 6, 2017 | 7.8 | 24 | NO | NO |
CVE-2019-13013MEDIUM Little Snitch versions 4.3.0 to 4.3.2 have a local privilege escalation vulnerability in their privileged helper tool. The privileged helper tool implements an XPC interface which | Aug 23, 2019 | 5.5 | 21 | NO | NO |
CVE-2019-13014MEDIUM Little Snitch versions 4.4.0 fixes a vulnerability in a privileged helper tool. However, the operating system may have made a copy of the privileged helper which is not removed or | Aug 23, 2019 | 5.5 | 19 | NO | NO |
CVE-2018-10470MEDIUM Little Snitch versions 4.0 to 4.0.6 use the SecStaticCodeCheckValidityWithErrors() function without the kSecCSCheckAllArchitectures flag and therefore do not validate all architect | Jun 12, 2018 | 5.3 | 19 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (6 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by Objective Development Software GmbH as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Objective Development Software GmbH as a CNA — matched by CVE ID, not by organization name.