CVE-2014-2956
ScriptHelperApi in the AVG ScriptHelper ActiveX control in ScriptHelper.exe in AVG Secure Search toolbar before 18.1.7.598 and AVG Safeguard before 18.1.7.644 does not implement domain-based access control for method calls, which allows remote attackers to trigger the downloading and execution of arbitrary programs via a crafted web site.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0137 (1.4%)
Percentile: 80.3%
EPSS: 2026-05-06
Affects
avg:safeguardavg:secure_search_toolbarTechnical description
ScriptHelperApi in the AVG ScriptHelper ActiveX control in ScriptHelper.exe in AVG Secure Search toolbar before 18.1.7.598 and AVG Safeguard before 18.1.7.644 does not implement domain-based access control for method calls, which allows remote attackers to trigger the downloading and execution of arbitrary programs via a crafted web site.
Published: 7/8/2014, 11:06:01 AM
Last modified: 5/6/2026, 10:30:45 PM