CVE-2014-1646

Symantec PGP Desktop <10.3.2 MP1 - DoS

Title source: llm
STIX 2.1

Description

Symantec PGP Desktop 10.0.x through 10.2.x and Encryption Desktop Professional 10.3.x before 10.3.2 MP1 do not properly perform memory copies, which allows remote attackers to cause a denial of service (read access violation and application crash) via a malformed certificate.

References (2)

Core 2

Scores

EPSS 0.0032
EPSS Percentile 54.9%

Details

CWE
CWE-119
Status published
Products (13)
symantec/encryption_desktop 10.3.0
symantec/encryption_desktop 10.3.1
symantec/encryption_desktop 10.3.2
symantec/pgp_desktop 10.0.0
symantec/pgp_desktop 10.0.1
symantec/pgp_desktop 10.0.2
symantec/pgp_desktop 10.0.3
symantec/pgp_desktop 10.1.0
symantec/pgp_desktop 10.1.1
symantec/pgp_desktop 10.1.2
... and 3 more
Published Apr 23, 2014
Tracked Since Feb 18, 2026