Objective Development Software GmbH produces Little Snitch, a macOS application that monitors and controls network traffic at the system level, presenting a narrow but privileged attack surface centered on process monitoring and network policy enforcement. Its disclosures cluster around local privilege escalation and memory-safety issues, including symlink-following conditions, buffer-boundary violations, and incomplete state cleanup, reflecting the kernel-adjacent role of network-filtering software. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Objective Development Software GmbH over time
Of all the CVEs published by Objective Development Software GmbH as a CNA, 83.3% affect products that Objective Development Software GmbH develops as a vendor.
Of all the CVEs published that affect products developed by Objective Development Software GmbH, 100.0% are self-published by Objective Development Software GmbH as a CNA.
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-13095HIGH Little Snitch version 4.5.1 and older changed ownership of a directory path controlled by the user. This allowed the user to escalate to root by linking the path to a directory con | Jun 30, 2020 | 8.8 | 28 | NO | NO |
CVE-2016-8661HIGH Little Snitch version 3.0 through 3.6.1 suffer from a buffer overflow vulnerability that could be locally exploited which could lead to an escalation of privileges (EoP) and unauth | Nov 15, 2016 | 8.4 | 27 | NO | NO |
CVE-2017-2675HIGH Little Snitch version 3.0 through 3.7.3 suffer from a local privilege escalation vulnerability in the installer part. The vulnerability is related to the installation of the config | Apr 6, 2017 | 7.8 | 24 | NO | NO |
CVE-2019-13013MEDIUM Little Snitch versions 4.3.0 to 4.3.2 have a local privilege escalation vulnerability in their privileged helper tool. The privileged helper tool implements an XPC interface which | Aug 23, 2019 | 5.5 | 21 | NO | NO |
CVE-2019-13014MEDIUM Little Snitch versions 4.4.0 fixes a vulnerability in a privileged helper tool. However, the operating system may have made a copy of the privileged helper which is not removed or | Aug 23, 2019 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Objective Development Software GmbH.
Media articles that mention a CVE ID that affects a product developed by Objective Development Software GmbH — matched by CVE ID, not by vendor name.