Vulnerability Description
ScriptHelperApi in the AVG ScriptHelper ActiveX control in ScriptHelper.exe in AVG Secure Search toolbar before 18.1.7.598 and AVG Safeguard before 18.1.7.644 does not implement domain-based access control for method calls, which allows remote attackers to trigger the downloading and execution of arbitrary programs via a crafted web site.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Avg | Safeguard | <= 18.1.7 |
| Avg | Secure Search Toolbar | <= 18.1.7 |
Related Weaknesses (CWE)
References
- http://www.kb.cert.org/vuls/id/960193US Government Resource
- http://www.kb.cert.org/vuls/id/960193US Government Resource
FAQ
What is CVE-2014-2956?
CVE-2014-2956 is a vulnerability with a CVSS score of 9.3 (HIGH). ScriptHelperApi in the AVG ScriptHelper ActiveX control in ScriptHelper.exe in AVG Secure Search toolbar before 18.1.7.598 and AVG Safeguard before 18.1.7.644 does not implement domain-based access co...
How severe is CVE-2014-2956?
CVE-2014-2956 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-2956?
Check the references section above for vendor advisories and patch information. Affected products include: Avg Safeguard, Avg Secure Search Toolbar.