CVE Database
/

CVE-2014-2956

Back to search

CVE-2014-2956

Published: Jul 8, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

ScriptHelperApi in the AVG ScriptHelper ActiveX control in ScriptHelper.exe in AVG Secure Search toolbar before 18.1.7.598 and AVG Safeguard before 18.1.7.644 does not implement domain-based access control for method calls, which allows remote attackers to trigger the downloading and execution of arbitrary programs via a crafted web site.

VendorProductVersions

n/a

n/a

affected
n/a

References

VU#960193
third-party-advisory
x_refsource_CERT-VN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now