VendorsSamsungkiesall versions
Vulnerabilities

Samsung Kies

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2012-6429
Buffer overflow in the PrepareSync method in the SyncService.dll ActiveX control in Samsung Kies before 2.5.1.12123_2_7 allows remote attackers to execute arbitrary code via a long string to the password argument.
Published 2014-04-04 · Modified
10.01 PoCEPSS 0.155
CVE-2012-3807
Samsung Kies before 2.5.0.12094_27_11 has arbitrary file execution.
Published 2020-01-09 · Modified
9.81 PoCEPSS 0.316
CVE-2012-2990
The MASetupCaller ActiveX control before 1.4.2012.508 in MASetupCaller.dll in MarkAny ContentSAFER, as distributed in Samsung KIES before 2.3.2.12074_13_13, does not properly implement unspecified methods, which allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via a crafted HTML document.
Published 2012-08-24 · Modified
9.3EPSS 0.037
CVE-2022-27843
DLL hijacking vulnerability in Kies prior to version 2.6.4.22014_2 allows attacker to execute abitrary code.
Published 2022-04-11 · Modified
7.8EPSS 0.002
CVE-2022-30744
DLL hijacking vulnerability in KiesWrapper in Samsung Kies prior to version 2.6.4.22043_1 allows attacker to execute arbitrary code.
Published 2022-06-07 · Modified
7.8EPSS 0.002
CVE-2012-3808
Samsung Kies before 2.5.0.12094_27_11 has arbitrary file modification.
Published 2020-01-09 · Modified
7.51 PoCEPSS 0.050
CVE-2012-3809
Samsung Kies before 2.5.0.12094_27_11 has arbitrary directory modification.
Published 2020-01-09 · Modified
7.51 PoCEPSS 0.050
CVE-2012-3810
Samsung Kies before 2.5.0.12094_27_11 has registry modification.
Published 2020-01-09 · Modified
7.51 PoCEPSS 0.050
CVE-2012-3806
Samsung Kies before 2.5.0.12094_27_11 contains a NULL pointer dereference vulnerability which could allow remote attackers to perform a denial of service.
Published 2020-01-09 · Modified
7.5EPSS 0.037
CVE-2022-39845
Improper validation of integrity check vulnerability in Samsung Kies prior to version 2.6.4.22074 allows local attackers to delete arbitrary directory using directory junction.
Published 2022-09-09 · Modified
7.1EPSS 0.001
CVE-2015-8780
Samsung wssyncmlnps before 2015-10-31 allows directory traversal in a Kies restore, aka ZipFury.
Published 2017-04-13 · Modified
6.9EPSS 0.006