Unrated severityNVD Advisory· Published Jul 8, 2014· Updated May 6, 2026
CVE-2014-2956
CVE-2014-2956
Description
ScriptHelperApi in the AVG ScriptHelper ActiveX control in ScriptHelper.exe in AVG Secure Search toolbar before 18.1.7.598 and AVG Safeguard before 18.1.7.644 does not implement domain-based access control for method calls, which allows remote attackers to trigger the downloading and execution of arbitrary programs via a crafted web site.
Affected products
2- cpe:2.3:a:avg:secure_search_toolbar:*:*:*:*:*:*:*:*Range: <=18.1.7
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.kb.cert.org/vuls/id/960193nvdUS Government Resource
News mentions
0No linked articles in our index yet.