CVE-2014-3436: Symantec Encryption Desktop
Medium severity, CVSS 5.0. EPSS: 1.1% chance of exploitation in the next 30 days.
Symantec Encryption Desktop 10.3.x before 10.3.2 MP3, and Symantec PGP Desktop 10.0.x through 10.2.x, allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted encrypted e-mail message that decompresses to a larger size.
Affected products
- Symantec Encryption Desktop: version 10.3.0 only; version 10.3.1 only; version 10.3.2 only
- Symantec Pgp Desktop: version 10.0.0 only; version 10.0.1 only; version 10.0.2 only; version 10.0.3 only; version 10.1.0 only; version 10.1.1 only; …
Published 2014-08-22. Last modified 2026-06-17.