ScriptHelperApi in the AVG ScriptHelper ActiveX control in ScriptHelper.exe in AVG Secure Search toolbar before 18.1.7.598 and AVG Safeguard before 18.1.7.644 does not implement domain-based access control for method calls, which allows remote attackers to trigger the downloading and execution of arbitrary programs via a crafted web site.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
http://www.kb.cert.org/vuls/id/960193 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: certcc
Published: 2014-07-08T10:00:00
Updated: 2024-08-06T10:28:45.999Z
Reserved: 2014-04-21T00:00:00
Link: CVE-2014-2956
Vulnrichment
No data.
NVD
Status : Modified
Published: 2014-07-08T11:06:01.483
Modified: 2024-11-21T02:07:14.373
Link: CVE-2014-2956
Redhat
No data.