Vulnerabilities > Samsung > Kies > Critical

DATE CVE VULNERABILITY TITLE RISK
2014-04-04 CVE-2012-6429 Buffer Errors vulnerability in Samsung Kies 2.3.2.12074/2.3.2.120741313/2.5.0.120942711
Buffer overflow in the PrepareSync method in the SyncService.dll ActiveX control in Samsung Kies before 2.5.1.12123_2_7 allows remote attackers to execute arbitrary code via a long string to the password argument.
network
low complexity
samsung CWE-119
critical
10.0
2012-08-24 CVE-2012-2990 Code Injection vulnerability in Samsung Kies 2.3.2.12074
The MASetupCaller ActiveX control before 1.4.2012.508 in MASetupCaller.dll in MarkAny ContentSAFER, as distributed in Samsung KIES before 2.3.2.12074_13_13, does not properly implement unspecified methods, which allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via a crafted HTML document.
network
samsung CWE-94
critical
9.3