VYPR
Unrated severityNVD Advisory· Published Dec 31, 2013· Updated Apr 29, 2026

CVE-2013-3667

CVE-2013-3667

Description

The software update mechanism as used in Bare Bones Software Yojimbo before 4.0, TextWrangler before 4.5.3, and BBEdit before 10.5.5 does not properly download and verify updates before installation, which allows attackers to perform "tampering or corruption" of the updates.

Affected products

35
  • cpe:2.3:a:barebones:textwrangler:*:*:*:*:*:*:*:*+ 10 more
    • cpe:2.3:a:barebones:textwrangler:*:*:*:*:*:*:*:*range: <=4.5.2
    • cpe:2.3:a:barebones:textwrangler:2.3:*:*:*:*:*:*:*
    • cpe:2.3:a:barebones:textwrangler:3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:barebones:textwrangler:3.5:*:*:*:*:*:*:*
    • cpe:2.3:a:barebones:textwrangler:3.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:barebones:textwrangler:3.5.3:*:*:*:*:*:*:*
    • cpe:2.3:a:barebones:textwrangler:4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:barebones:textwrangler:4.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:barebones:textwrangler:4.5:*:*:*:*:*:*:*
    • cpe:2.3:a:barebones:textwrangler:4.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:barebones:textwrangler:3.1:*:*:*:*:*:*:*
  • Barebones/Bbedit10 versions
    cpe:2.3:a:barebones:bbedit:*:*:*:*:*:*:*:*+ 9 more
    • cpe:2.3:a:barebones:bbedit:*:*:*:*:*:*:*:*range: <=10.5.4
    • cpe:2.3:a:barebones:bbedit:10.0:*:*:*:*:*:*:*
    • cpe:2.3:a:barebones:bbedit:10.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:barebones:bbedit:10.1:*:*:*:*:*:*:*
    • cpe:2.3:a:barebones:bbedit:10.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:barebones:bbedit:10.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:barebones:bbedit:10.5:*:*:*:*:*:*:*
    • cpe:2.3:a:barebones:bbedit:10.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:barebones:bbedit:10.5.2:*:*:*:*:*:*:*
    • cpe:2.3:a:barebones:bbedit:10.5.3:*:*:*:*:*:*:*
  • Barebones/Yojimbo14 versions
    cpe:2.3:a:barebones:yojimbo:*:*:*:*:*:*:*:*+ 13 more
    • cpe:2.3:a:barebones:yojimbo:*:*:*:*:*:*:*:*range: <=3.0.4
    • cpe:2.3:a:barebones:yojimbo:1.4:*:*:*:*:*:*:*
    • cpe:2.3:a:barebones:yojimbo:1.4.1:*:*:*:*:*:*:*
    • cpe:2.3:a:barebones:yojimbo:1.4.2:*:*:*:*:*:*:*
    • cpe:2.3:a:barebones:yojimbo:1.5:*:*:*:*:*:*:*
    • cpe:2.3:a:barebones:yojimbo:1.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:barebones:yojimbo:1.5.2:*:*:*:*:*:*:*
    • cpe:2.3:a:barebones:yojimbo:2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:barebones:yojimbo:2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:barebones:yojimbo:2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:barebones:yojimbo:3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:barebones:yojimbo:3.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:barebones:yojimbo:3.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:barebones:yojimbo:3.0.1:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.