CVE-2014-3912: Samsung Ipolis Device Manager

High severity, CVSS 9.3. EPSS: 4.4% chance of exploitation in the next 30 days.

Stack-based buffer overflow in the FindConfigChildeKeyList method in the XNSSDKDEVICE.XnsSdkDeviceCtrlForIpInstaller.1 ActiveX control in Samsung iPOLiS Device Manager before 1.8.7 allows remote attackers to execute arbitrary code via a long value.

Affected products

  • Samsung Ipolis Device Manager: up to and including 1.8.2

Published 2014-06-05. Last modified 2026-06-17.