A remote user can create a specially crafted archive file that, when processed by the target user with the KDE Ark tool, will issue XMLHttpRequests to arbitrary sites.
A local user with the ability to set specially crafted 'TREENAME' or 'GROUPNAME' values in the spd files can trigger a stack overflow and execute arbitrary code. The code will run with the privileges of the SoftRemote client.