CVE-2007-0018
Description
Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. NOTE: the products include (1) NCTsoft NCTAudioStudio, NCTAudioEditor, and NCTDialogicVoice; (2) Magic Audio Recorder, Music Editor, and Audio Converter; (3) Aurora Media Workshop; DB Audio Mixer And Editor; (4) J. Hepple Products including Fx Audio Editor and others; (5) EXPStudio Audio Editor; (6) iMesh; (7) Quikscribe; (8) RMBSoft AudioConvert and SoundEdit Pro 2.1; (9) CDBurnerXP; (10) Code-it Software Wave MP3 Editor and aBasic Editor; (11) Movavi VideoMessage, DVD to iPod, and others; (12) SoftDiv Software Dexster, iVideoMAX, and others; (13) Sienzo Digital Music Mentor (DMM); (14) MP3 Normalizer; (15) Roemer Software FREE and Easy Hi-Q Recorder, and Easy Hi-Q Converter; (16) Audio Edit Magic; (17) Joshua Video and Audio Converter; (18) Virtual CD; (19) Cheetah CD and DVD Burner; (20) Mystik Media AudioEdit Deluxe, Blaze Media, and others; (21) Power Audio Editor; (22) DanDans Digital Media Full Audio Converter, Music Editing Master, and others; (23) Xrlly Software Text to Speech Makerand Arial Sound Recorder / Audio Converter; (24) Absolute Sound Recorder, Video to Audio Converter, and MP3 Splitter; (25) Easy Ringtone Maker; (26) RecordNRip; (27) McFunSoft iPod Audio Studio, Audio Recorder for Free, and others; (28) MP3 WAV Converter; (29) BearShare 6.0.2.26789; and (30) Oracle Siebel SimBuilder and CRM 7.x.
Affected Products
50 of 83| Vendor | Product | Version |
|---|---|---|
| altdo | convert_mp3_master |
1.1
|
| altdo | mp3_record_and_edit_audio_master |
1.2
|
| americanshareware | mp3_wav_converter |
3.1.8
|
| audio_edit_magic | audio_edit_magic |
9.2.3_389
|
| bearshare | bearshare |
6.0.2.26789
|
| cdburnerxp | cdburnerxp_pro |
3.0.116
|
| cheetahburner | cheetah_cd_burner |
3.56
|
| cheetahburner | cheetah_dvd_burner |
1.79
|
| code-it_softare | abasic_editor |
10.1
|
| code-it_softare | wave_mp3_editor |
10.1
|
| dandans_digital_media_products | easy_audio_editor |
7.4
|
| dandans_digital_media_products | full_audio_converter |
4.2
|
| dandans_digital_media_products | music_editing_master |
5.2
|
| dandans_digital_media_products | visual_video_converter |
4.4
|
| digital_borneo | audio_mixer_and_editor |
1.1.0
|
| easy_ringtone_maker | easy_ringtone_maker |
2.0.5
|
| expstudio | audio_editor |
4.0.2
|
| iaudiosoft.com | absolute_mp3_splitter |
2.5.4
|
| iaudiosoft.com | absolute_sound_recorder |
3.4.5
|
| iaudiosoft.com | absolute_video_to_audio_converter |
2.7.9
|
| imesh.com | imesh |
7.0.2.26789
|
| j_hepple_products | fx_audio_concat |
1.2.0_beta
|
| j_hepple_products | fx_audio_editor |
4.7.11
|
| j_hepple_products | fx_audio_tools |
7.3.4
|
| j_hepple_products | fx_magic_music |
5.7.7
|
| j_hepple_products | fx_movie_joiner |
6.2.8
|
| j_hepple_products | fx_movie_joiner_and_splitter |
6.2.8
|
| j_hepple_products | fx_movie_splitter |
6.4.7
|
| j_hepple_products | fx_new_sound |
5.1.1
|
| j_hepple_products | fx_video_converter |
7.51.21
|
| joshua_mediasoft | audio_convertor_plus |
2.2
|
| joshua_mediasoft | video_converter_plus |
3.01
|
| magicvideosoftare | magic_audio_converter |
8.2.6_build_719
|
| magicvideosoftare | magic_audio_recorder |
5.3.7
|
| magicvideosoftare | magic_music_editor |
5.2.2
|
| mcfunsoft | audio_editor |
6.3.3_build_489
|
| mcfunsoft | audio_recorder_for_free |
6.1
|
| mcfunsoft | audio_studio |
6.6.3_build_479
|
| mcfunsoft | ipod_audio_studio |
6.2.4
|
| mcfunsoft | ipod_music_converter |
5.1
|
| mcfunsoft | recording_to_ipod_solution |
5.1
|
| mediatox | aurora_media_workshop |
3.3.25
|
| movavi | chiliburner |
2.3
|
| movavi | convertmovie |
4.4
|
| movavi | dvd_to_ipod |
1.0
|
| movavi | splitmovie |
1.4
|
| movavi | suite |
3.5
|
| movavi | videomessage |
1.0
|
| mp3-soft | mp3_normalizer |
1.03
|
| mystik_media_products | audioedit_deluxe |
4.10
|
References
Weakness Types
CVE Information
- CVE ID:
CVE-2007-0018- Published:
- 2007-01-24
- Modified:
- 2026-04-23
- CVSS Score:
- 9.3
- Severity:
- HIGH
- Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C