Little Snitch
Vendor:
First CVE: Nov 15, 2016 · Active for 9 years
5
Total CVEs
More Total CVEs than 79% of tracked products
1.3
Avg CVEs / Year
Higher CVE frequency than 58% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 47% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Little Snitch over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 15, 2016
9 years ago
Most Recent CVE
Jun 30, 2020
2,218 days ago
CVE Severity & Scoring
Little Snitch5 CVEs
40%
60%
All CVEs352,785 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local4 (80.0%)
Network1 (20.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (80.0%)
High0 (0.0%)
None1 (20.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-13095HIGH Little Snitch version 4.5.1 and older changed ownership of a directory path controlled by the user. This allowed the user to escalate to root by linking the path to a directory con | Jun 30, 2020 | 8.8 | 28 | NO | NO |
CVE-2016-8661HIGH Little Snitch version 3.0 through 3.6.1 suffer from a buffer overflow vulnerability that could be locally exploited which could lead to an escalation of privileges (EoP) and unauth | Nov 15, 2016 | 8.4 | 27 | NO | NO |
CVE-2017-2675HIGH Little Snitch version 3.0 through 3.7.3 suffer from a local privilege escalation vulnerability in the installer part. The vulnerability is related to the installation of the config | Apr 6, 2017 | 7.8 | 24 | NO | NO |
CVE-2019-13013MEDIUM Little Snitch versions 4.3.0 to 4.3.2 have a local privilege escalation vulnerability in their privileged helper tool. The privileged helper tool implements an XPC interface which | Aug 23, 2019 | 5.5 | 21 | NO | NO |
CVE-2019-13014MEDIUM Little Snitch versions 4.4.0 fixes a vulnerability in a privileged helper tool. However, the operating system may have made a copy of the privileged helper which is not removed or | Aug 23, 2019 | 5.5 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Little Snitch
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.4.0 | 1 | 5.5 | 0.4% | 0 | 0 |
| 3.6.1 | 2 | 8.1 | 0.4% | 0 | 0 |
| 3.6 | 2 | 8.1 | 0.4% | 0 | 0 |
| 3.5.3 | 2 | 8.1 | 0.4% | 0 | 0 |
| 3.5.2 | 2 | 8.1 | 0.4% | 0 | 0 |
| 3.5.1 | 2 | 8.1 | 0.4% | 0 | 0 |
| 3.5 | 2 | 8.1 | 0.4% | 0 | 0 |
| 3.4.2 | 2 | 8.1 | 0.4% | 0 | 0 |
| 3.4.1 | 2 | 8.1 | 0.4% | 0 | 0 |
| 3.4 | 2 | 8.1 | 0.4% | 0 | 0 |
| 3.3.4 | 2 | 8.1 | 0.4% | 0 | 0 |
| 3.3.3 | 2 | 8.1 | 0.4% | 0 | 0 |
| 3.3.2 | 2 | 8.1 | 0.4% | 0 | 0 |
| 3.3.1 | 2 | 8.1 | 0.4% | 0 | 0 |
| 3.3 | 2 | 8.1 | 0.4% | 0 | 0 |
| 3.1.1 | 2 | 8.1 | 0.4% | 0 | 0 |
| 3.1 | 2 | 8.1 | 0.4% | 0 | 0 |
| 3.0.4 | 2 | 8.1 | 0.4% | 0 | 0 |
| 3.0.3 | 2 | 8.1 | 0.4% | 0 | 0 |
| 3.0.2 | 2 | 8.1 | 0.4% | 0 | 0 |