Buffer overflow in the PrepareSync method in the SyncService.dll ActiveX control in Samsung Kies before 2.5.1.1212327 allows remote attackers to execute arbitrary code via a long string to the password argument.
Samsung Kies before 2.5.0.120942711 has arbitrary file execution.
The MASetupCaller ActiveX control before 1.4.2012.508 in MASetupCaller.dll in MarkAny ContentSAFER, as distributed in Samsung KIES before 2.3.2.120741313, does not properly implement unspecified methods, which allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via a crafted HTML document.
DLL hijacking vulnerability in Kies prior to version 2.6.4.220142 allows attacker to execute abitrary code.
DLL hijacking vulnerability in KiesWrapper in Samsung Kies prior to version 2.6.4.220431 allows attacker to execute arbitrary code.
Samsung Kies before 2.5.0.120942711 has registry modification.
Samsung Kies before 2.5.0.120942711 has arbitrary directory modification.
Samsung Kies before 2.5.0.120942711 contains a NULL pointer dereference vulnerability which could allow remote attackers to perform a denial of service.
Samsung Kies before 2.5.0.120942711 has arbitrary file modification.
Improper validation of integrity check vulnerability in Samsung Kies prior to version 2.6.4.22074 allows local attackers to delete arbitrary directory using directory junction.
Samsung wssyncmlnps before 2015-10-31 allows directory traversal in a Kies restore, aka ZipFury.
Samsung Kies Air 2.1.207051 and 2.1.210161 allows remote attackers to cause a denial of service (crash) via a crafted request to www/apps/KiesAir/jws/ssd.php.
Samsung Kies Air 2.1.207051 and 2.1.210161 relies on the IP address for authentication, which allows remote man-in-the-middle attackers to read arbitrary phone contents by spoofing or controlling the IP address.