9.3

CVE-2007-0018

Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. NOTE: the products include (1) NCTsoft NCTAudioStudio, NCTAudioEditor, and NCTDialogicVoice; (2) Magic Audio Recorder, Music Editor, and Audio Converter; (3) Aurora Media Workshop; DB Audio Mixer And Editor; (4) J. Hepple Products including Fx Audio Editor and others; (5) EXPStudio Audio Editor; (6) iMesh; (7) Quikscribe; (8) RMBSoft AudioConvert and SoundEdit Pro 2.1; (9) CDBurnerXP; (10) Code-it Software Wave MP3 Editor and aBasic Editor; (11) Movavi VideoMessage, DVD to iPod, and others; (12) SoftDiv Software Dexster, iVideoMAX, and others; (13) Sienzo Digital Music Mentor (DMM); (14) MP3 Normalizer; (15) Roemer Software FREE and Easy Hi-Q Recorder, and Easy Hi-Q Converter; (16) Audio Edit Magic; (17) Joshua Video and Audio Converter; (18) Virtual CD; (19) Cheetah CD and DVD Burner; (20) Mystik Media AudioEdit Deluxe, Blaze Media, and others; (21) Power Audio Editor; (22) DanDans Digital Media Full Audio Converter, Music Editing Master, and others; (23) Xrlly Software Text to Speech Makerand Arial Sound Recorder / Audio Converter; (24) Absolute Sound Recorder, Video to Audio Converter, and MP3 Splitter; (25) Easy Ringtone Maker; (26) RecordNRip; (27) McFunSoft iPod Audio Studio, Audio Recorder for Free, and others; (28) MP3 WAV Converter; (29) BearShare 6.0.2.26789; and (30) Oracle Siebel SimBuilder and CRM 7.x.

Data is provided by the National Vulnerability Database (NVD)
AltdoConvert Mp3 Master Version1.1
Audio Edit MagicAudio Edit Magic Version9.2.3_389
BearshareBearshare Version6.0.2.26789
CdburnerxpCdburnerxp Pro Version3.0.116
Code-it SoftareAbasic Editor Version10.1
ExpstudioAudio Editor Version4.0.2
Imesh.ComImesh Version7.0.2.26789
J Hepple ProductsFx Audio Concat Version1.2.0_beta
J Hepple ProductsFx New Sound Version5.1.1
MagicvideosoftareMagic Audio Converter Version8.2.6_build_719
McfunsoftAudio Editor Version6.3.3_build_489
McfunsoftAudio Studio Version6.6.3_build_479
McfunsoftIpod Audio Studio Version6.2.4
MediatoxAurora Media Workshop Version3.3.25
MovaviChiliburner Version2.3
MovaviConvertmovie Version4.4
MovaviDvd To Ipod Version1.0
MovaviSplitmovie Version1.4
MovaviSuite Version3.5
MovaviVideomessage Version1.0
Mp3-softMp3 Normalizer Version1.03
Nctsoft ProductsNctaudioeditor Version2.7.1
Nctsoft ProductsNctaudiostudio Version2.7.1
Nextlevel SystemsAudio Editor Gold Version9.2.5_build_424
Nextlevel SystemsAudio Studio Gold Version7.0.1.1_build_500
QuikscribeQuikscribe Player Version5.022.05
QuikscribeQuikscribe Recorder Version5.021.29
RecordnripRecordnrip Version1.0
RmbsoftAudioconvert Version3.1.0.125
RmbsoftSoundedit Pro Version2.1
SienzoDigital Music Mentor Version2.6.0.3
Softdiv SoftareDexster Version3.0
Softdiv SoftareIvideomax Version3.9
Softdiv SoftareSnosh Version1.4
Softdiv SoftareVideozilla Version2.5
Virtual CdVirtual Cd Version6.0.0.7
Virtual CdVirtual Cd Version7.1.0.2
Virtual CdVirtual Cd Version8.0.0.6
Virtual CdVirtual Cd File Server Version7.1.0.3
Xwaver.ComMagic Audio Editor Pro Version10.3.1_build_476
Xwaver.ComMagic Music Studio Pro Version7.0.2.1_build_500
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 72.47% 0.987
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.