Objective Development's vulnerability profile clusters around a small portfolio of macOS and network utility tools including Little Snitch, Sharity, and WebYep, with observed weaknesses centered on code injection, cryptographic signature verification, and control-flow issues in application and system-integration code. Treat this as a compact, focused vendor profile; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Objective Development over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-5220MEDIUM Multiple PHP remote file inclusion vulnerabilities in WebYep 1.1.9, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via the webyep_sIncludePa | Oct 10, 2006 | 5.1 | 26 | NO | YES |
CVE-2008-4057HIGH Unspecified vulnerability in Objective Development Sharity 3 before 3.5 has unknown impact and attack vectors, related to a "serious security problem." | Sep 11, 2008 | 10.0 | 25 | NO | NO |
CVE-2017-2675HIGH Little Snitch version 3.0 through 3.7.3 suffer from a local privilege escalation vulnerability in the installer part. The vulnerability is related to the installation of the config | Apr 6, 2017 | 7.8 | 24 | NO | NO |
CVE-2007-2178HIGH Multiple unspecified vulnerabilities in Objective Development Sharity before 3.3 allow remote attackers to cause a denial of service (daemon crash) via unspecified vectors. | Apr 24, 2007 | 7.8 | 20 | NO | NO |
CVE-2018-10470MEDIUM Little Snitch versions 4.0 to 4.0.6 use the SecStaticCodeCheckValidityWithErrors() function without the kSecCSCheckAllArchitectures flag and therefore do not validate all architect | Jun 12, 2018 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Objective Development.
Media articles that mention a CVE ID that affects a product developed by Objective Development — matched by CVE ID, not by vendor name.