CVE-2007-0018 - CVE House
Back to Database
Status published Critical CVE-2007-0018

Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as...

Vulnerability Description

Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. NOTE: the products include (1) NCTsoft NCTAudioStudio, NCTAudioEditor, and NCTDialogicVoice; (2) Magic Audio Recorder, Music Editor, and Audio Converter; (3) Aurora Media Workshop; DB Audio Mixer And Editor; (4) J. Hepple Products including Fx Audio Editor and others; (5) EXPStudio Audio Editor; (6) iMesh; (7) Quikscribe; (8) RMBSoft AudioConvert and SoundEdit Pro 2.1; (9) CDBurnerXP; (10) Code-it Software Wave MP3 Editor and aBasic Editor; (11) Movavi VideoMessage, DVD to iPod, and others; (12) SoftDiv Software Dexster, iVideoMAX, and others; (13) Sienzo Digital Music Mentor (DMM); (14) MP3 Normalizer; (15) Roemer Software FREE and Easy Hi-Q Recorder, and Easy Hi-Q Converter; (16) Audio Edit Magic; (17) Joshua Video and Audio Converter; (18) Virtual CD; (19) Cheetah CD and DVD Burner; (20) Mystik Media AudioEdit Deluxe, Blaze Media, and others; (21) Power Audio Editor; (22) DanDans Digital Media Full Audio Converter, Music Editing Master, and others; (23) Xrlly Software Text to Speech Makerand Arial Sound Recorder / Audio Converter; (24) Absolute Sound Recorder, Video to Audio Converter, and MP3 Splitter; (25) Easy Ringtone Maker; (26) RecordNRip; (27) McFunSoft iPod Audio Studio, Audio Recorder for Free, and others; (28) MP3 WAV Converter; (29) BearShare 6.0.2.26789; and (30) Oracle Siebel SimBuilder and CRM 7.x.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-0018

Credits & Attribution

No credits recorded in the NVD database.

References

Affected Vendor

Affected Software

convert mp3 master, mp3 record and edit audio master, mp3 wav converter, audio edit magic, bearshare, cdburnerxp pro, cheetah cd burner, cheetah dvd burner, abasic editor, wave mp3 editor, easy audio editor, full audio converter, music editing master, visual video converter, audio mixer and editor, easy ringtone maker, audio editor, absolute mp3 splitter, absolute sound recorder, absolute video to audio converter, imesh, fx audio concat, fx audio editor, fx audio tools, fx magic music, fx movie joiner, fx movie joiner and splitter, fx movie splitter, fx new sound, fx video converter, audio convertor plus, video converter plus, magic audio converter, magic audio recorder, magic music editor, audio recorder for free, audio studio, ipod audio studio, ipod music converter, recording to ipod solution, aurora media workshop, chiliburner, convertmovie, dvd to ipod, splitmovie, suite, videomessage, mp3 normalizer, audioedit deluxe, blaze media pro, blaze mediaconvert, contextconvert pro, nctaudioeditor, nctaudiofile2, nctaudiostudio, nctdialogicvoice, audio editor gold, audio studio gold, quikscribe player, quikscribe recorder, recordnrip, audioconvert, soundedit pro, easy hi-q converter, easy hi-q recorder, free hi-q recorder, digital music mentor, power audio editor, dexster, ivideomax, mp3 to wav converter, snosh, videozilla, virtual cd, virtual cd file server, arial audio converter, arial sound recorder, text to speech maker, magic audio editor pro, magic music studio pro
Vulnerable Versions:
1.1, 1.2, 3.1.8, 9.2.3_389, 6.0.2.26789, 3.0.116, 3.56, 1.79, 10.1, 7.4, 4.2, 5.2, 4.4, 1.1.0, 2.0.5, 4.0.2, 2.5.4, 3.4.5, 2.7.9, 7.0.2.26789, 1.2.0_beta, 4.7.11, 7.3.4, 5.7.7, 6.2.8, 6.4.7, 5.1.1, 7.51.21, 2.2, 3.01, 8.2.6_build_719, 5.3.7, 5.2.2, 6.3.3_build_489, 6.1, 6.6.3_build_479, 6.2.4, 5.1, 3.3.25, 2.3, 1.0, 1.4, 3.5, 1.03, 4.10, 7.0, 3.4, 3.1, 2.7.1, 9.2.5_build_424, 7.0.1.1_build_500, 5.022.05, 5.021.29, 3.1.0.125, 2.1, 1.7, 2.0, 1.9, 2.6.0.3, 11.0.1, 3.0, 3.9, 2.5, 6.0.0.7, 7.1.0.2, 8.0.0.6, 7.1.0.3, 2.3.40, 1.4.3, 1.3.8, 10.3.1_build_476, 7.0.2.1_build_500

Timeline

Official Publish: January 24th, 2007
Last Modified: August 7th, 2024
Added to House: July 18th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.