{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-03T03:52:52.904","vulnerabilities":[{"cve":{"id":"CVE-2018-10470","sourceIdentifier":"office@obdev.at","published":"2018-06-12T17:29:00.207","lastModified":"2026-06-17T01:34:00.407","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Little Snitch versions 4.0 to 4.0.6 use the SecStaticCodeCheckValidityWithErrors() function without the kSecCSCheckAllArchitectures flag and therefore do not validate all architectures stored in a fat binary. An attacker can maliciously craft a fat binary containing multiple architectures that may cause a situation where Little Snitch treats the running process as having no code signature at all while erroneously indicating that the binary on disk does have a valid code signature. This could lead to users being confused about whether or not the code signature is valid."},{"lang":"es","value":"Little Snitch desde la versión 4.0 hasta la 4.0.6 emplea la función SecStaticCodeCheckValidityWithErrors() sin el flag kSecCSCheckAllArchitectures y, por lo tanto, no valida todas las arquitecturas almacenadas en un binario fat. Un atacante puede manipular maliciosamente un binario fat que contenga múltiples arquitecturas que podría provocar una situación por la que Little Snitch considera que el proceso en ejecución no tiene firma de código aunque indica que el binario en el disco tiene una firma de código válida. Esto podría conducir a que los usuarios estén confusos sobre si la firma de código es válida o no."}],"affected":[{"source":"office@obdev.at","affectedData":[{"vendor":"Objective Development Software GmbH","product":"Little Snitch","versions":[{"version":"4.0 - 4.0.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"office@obdev.at","type":"Secondary","description":[{"lang":"en","value":"CWE-347"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-347"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:objective_development:little_snitch:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0","versionEndIncluding":"4.0.6","matchCriteriaId":"14CA0E0C-AAE6-4E95-A4F9-928DDDA89E1C"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*","matchCriteriaId":"387021A0-AF36-463C-A605-32EA7DAC172E"}]}]}],"references":[{"url":"https://obdev.at/cve/2018-10470-8FRWkW4oH8.html","source":"office@obdev.at"},{"url":"https://www.okta.com/security-blog/2018/06/issues-around-third-party-apple-code-signing-checks/","source":"office@obdev.at"},{"url":"https://obdev.at/cve/2018-10470-8FRWkW4oH8.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.okta.com/security-blog/2018/06/issues-around-third-party-apple-code-signing-checks/","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}