CVE Database
/

CVE-2007-0018

Back to search

CVE-2007-0018

Published: Jan 24, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. NOTE: the products include (1) NCTsoft NCTAudioStudio, NCTAudioEditor, and NCTDialogicVoice; (2) Magic Audio Recorder, Music Editor, and Audio Converter; (3) Aurora Media Workshop; DB Audio Mixer And Editor; (4) J. Hepple Products including Fx Audio Editor and others; (5) EXPStudio Audio Editor; (6) iMesh; (7) Quikscribe; (8) RMBSoft AudioConvert and SoundEdit Pro 2.1; (9) CDBurnerXP; (10) Code-it Software Wave MP3 Editor and aBasic Editor; (11) Movavi VideoMessage, DVD to iPod, and others; (12) SoftDiv Software Dexster, iVideoMAX, and others; (13) Sienzo Digital Music Mentor (DMM); (14) MP3 Normalizer; (15) Roemer Software FREE and Easy Hi-Q Recorder, and Easy Hi-Q Converter; (16) Audio Edit Magic; (17) Joshua Video and Audio Converter; (18) Virtual CD; (19) Cheetah CD and DVD Burner; (20) Mystik Media AudioEdit Deluxe, Blaze Media, and others; (21) Power Audio Editor; (22) DanDans Digital Media Full Audio Converter, Music Editing Master, and others; (23) Xrlly Software Text to Speech Makerand Arial Sound Recorder / Audio Converter; (24) Absolute Sound Recorder, Video to Audio Converter, and MP3 Splitter; (25) Easy Ringtone Maker; (26) RecordNRip; (27) McFunSoft iPod Audio Studio, Audio Recorder for Free, and others; (28) MP3 WAV Converter; (29) BearShare 6.0.2.26789; and (30) Oracle Siebel SimBuilder and CRM 7.x.

VendorProductVersions

n/a

n/a

affected
n/a

References

23546
third-party-advisory
x_refsource_SECUNIA
23892
vdb-entry
x_refsource_BID
23535
third-party-advisory
x_refsource_SECUNIA
nctaudiofile2-multiple-bo(31707)
vdb-entry
x_refsource_XF
23562
third-party-advisory
x_refsource_SECUNIA
23536
third-party-advisory
x_refsource_SECUNIA
30459
third-party-advisory
x_refsource_SECUNIA
30406
third-party-advisory
x_refsource_SECUNIA
23553
third-party-advisory
x_refsource_SECUNIA
23551
third-party-advisory
x_refsource_SECUNIA
23485
third-party-advisory
x_refsource_SECUNIA
23550
third-party-advisory
x_refsource_SECUNIA
30447
third-party-advisory
x_refsource_SECUNIA
23541
third-party-advisory
x_refsource_SECUNIA
26046
third-party-advisory
x_refsource_SECUNIA
23534
third-party-advisory
x_refsource_SECUNIA
23516
third-party-advisory
x_refsource_SECUNIA
25993
third-party-advisory
x_refsource_SECUNIA
23495
third-party-advisory
x_refsource_SECUNIA
23558
third-party-advisory
x_refsource_SECUNIA
23544
third-party-advisory
x_refsource_SECUNIA
23530
third-party-advisory
x_refsource_SECUNIA
23795
third-party-advisory
x_refsource_SECUNIA
23543
third-party-advisory
x_refsource_SECUNIA
23552
third-party-advisory
x_refsource_SECUNIA
23475
third-party-advisory
x_refsource_SECUNIA
23560
third-party-advisory
x_refsource_SECUNIA
30439
third-party-advisory
x_refsource_SECUNIA
26100
third-party-advisory
x_refsource_SECUNIA
23548
third-party-advisory
x_refsource_SECUNIA
30446
third-party-advisory
x_refsource_SECUNIA
30424
third-party-advisory
x_refsource_SECUNIA
23561
third-party-advisory
x_refsource_SECUNIA
23557
third-party-advisory
x_refsource_SECUNIA
23745
third-party-advisory
x_refsource_SECUNIA
28407
third-party-advisory
x_refsource_SECUNIA
23493
third-party-advisory
x_refsource_SECUNIA
23511
third-party-advisory
x_refsource_SECUNIA
ADV-2007-0310
vdb-entry
x_refsource_VUPEN
23565
third-party-advisory
x_refsource_SECUNIA
22922
third-party-advisory
x_refsource_SECUNIA
30450
third-party-advisory
x_refsource_SECUNIA
23568
third-party-advisory
x_refsource_SECUNIA
23532
third-party-advisory
x_refsource_SECUNIA
26101
third-party-advisory
x_refsource_SECUNIA
23753
third-party-advisory
x_refsource_SECUNIA
23542
third-party-advisory
x_refsource_SECUNIA
VU#292713
third-party-advisory
x_refsource_CERT-VN
23554
third-party-advisory
x_refsource_SECUNIA
22196
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now