Objective Development Software GmbH

First CVE: Nov 15, 2016Active for: 10 years
6
CVEs Published
More CVEs Published than 18% of tracked CNAs
1.2
Avg CVEs / Year
More Avg CVEs / Year than 7% of tracked CNAs
6.9
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Objective Development Software GmbH as a CNA, 83.3% affect products that Objective Development Software GmbH develops as a vendor.

83.3%
16.7%
Self-reported: 5Third-party: 1

Of all the CVEs published that affect products developed by Objective Development Software GmbH, 100.0% are self-published by Objective Development Software GmbH as a CNA.

100.0%
Self-published: 5Published by other CNAs: 0

Trends Over Time

The number and severity of CVEs published by Objective Development Software GmbH over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 15, 2016
9 years ago
Most Recent CVE
Jun 30, 2020
2,215 days ago

Top CVEs

All CVEs published by Objective Development Software GmbH as a CNA, regardless of affected vendor or product.

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Little Snitch version 4.5.1 and older changed ownership of a directory path controlled by the user. This allowed the user to escalate to root by linking the path to a directory con
Jun 30, 20208.828NONO
Little Snitch version 3.0 through 3.6.1 suffer from a buffer overflow vulnerability that could be locally exploited which could lead to an escalation of privileges (EoP) and unauth
Nov 15, 20168.427NONO
Little Snitch version 3.0 through 3.7.3 suffer from a local privilege escalation vulnerability in the installer part. The vulnerability is related to the installation of the config
Apr 6, 20177.824NONO
Little Snitch versions 4.3.0 to 4.3.2 have a local privilege escalation vulnerability in their privileged helper tool. The privileged helper tool implements an XPC interface which
Aug 23, 20195.521NONO
Little Snitch versions 4.4.0 fixes a vulnerability in a privileged helper tool. However, the operating system may have made a copy of the privileged helper which is not removed or
Aug 23, 20195.519NONO
Little Snitch versions 4.0 to 4.0.6 use the SecStaticCodeCheckValidityWithErrors() function without the kSecCSCheckAllArchitectures flag and therefore do not validate all architect
Jun 12, 20185.319NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA6 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHigh
Attack Vector
Local4 (66.7%)
Network2 (33.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (66.7%)
High0 (0.0%)
None2 (33.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Objective Development Software GmbH as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Objective Development Software GmbH as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs