AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2014-4677

HIGH · CVSS 7.8 EPSS 0.65%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-02-22 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2014-4677
Severity
HIGH
CVSS
7.8
EPSS
0.65%

Original Filing — NVD Description

The installPackage function in the installerHelper subcomponent in Libmacgpg in GPG Suite before 2015.06 allows local users to execute arbitrary commands with root privileges via shell metacharacters in the xmlPath argument.