← Back

CVE-2016-8661

nvd nist
Published: Nov 15, 2016Modified: May 6, 2026

JSON object

Loading...
8.4
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.5 / Impact: 5.9
Source: NVD

Description

Little Snitch version 3.0 through 3.6.1 suffer from a buffer overflow vulnerability that could be locally exploited which could lead to an escalation of privileges (EoP) and unauthorised ring0 access to the operating system. The buffer overflow is related to insufficient checking of parameters to the "OSMalloc" and "copyin" kernel API calls.

Affected (21)

Products: Obdev: Little Snitch
1 product
Little Snitch
Configuration A
21 vulnerable
Vulnerable SoftwareAffected Versions
Obdev
Version 3.0.1
Version 3.0.2
Version 3.0.3
Version 3.0.4
Version 3.0
Version 3.1.1
Version 3.1
Version 3.3.1
Version 3.3.2
Version 3.3.3
Version 3.3.4
Version 3.3
Version 3.4.1
Version 3.4.2
Version 3.4
Version 3.5.1
Version 3.5.2
Version 3.5.3
Version 3.5
Version 3.6.1
Version 3.6

Timeline

No history available yet.