CVE-2007-0018 (CNNVD-200701-427)
中文标题:
NCTsoft NCTAudioFile2 ActiveX控件远程栈溢出漏洞
英文标题:
Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as u...
漏洞描述
中文描述:
NCTAudioFile2是NCTsoft提供的一个ActiveX控件,用于处理音频数据。 NCTAudioFile2 ActiveX控件在处理带有畸形参数的SetFormatLikeSample()方法时存在栈溢出漏洞,远程攻击者可能利用此漏洞控制用户机器。如果攻击者能够向该方式发送超过4124字节的超长参数时,就可以触发这个溢出,导致执行任意指令。
英文描述:
Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. NOTE: the products include (1) NCTsoft NCTAudioStudio, NCTAudioEditor, and NCTDialogicVoice; (2) Magic Audio Recorder, Music Editor, and Audio Converter; (3) Aurora Media Workshop; DB Audio Mixer And Editor; (4) J. Hepple Products including Fx Audio Editor and others; (5) EXPStudio Audio Editor; (6) iMesh; (7) Quikscribe; (8) RMBSoft AudioConvert and SoundEdit Pro 2.1; (9) CDBurnerXP; (10) Code-it Software Wave MP3 Editor and aBasic Editor; (11) Movavi VideoMessage, DVD to iPod, and others; (12) SoftDiv Software Dexster, iVideoMAX, and others; (13) Sienzo Digital Music Mentor (DMM); (14) MP3 Normalizer; (15) Roemer Software FREE and Easy Hi-Q Recorder, and Easy Hi-Q Converter; (16) Audio Edit Magic; (17) Joshua Video and Audio Converter; (18) Virtual CD; (19) Cheetah CD and DVD Burner; (20) Mystik Media AudioEdit Deluxe, Blaze Media, and others; (21) Power Audio Editor; (22) DanDans Digital Media Full Audio Converter, Music Editing Master, and others; (23) Xrlly Software Text to Speech Makerand Arial Sound Recorder / Audio Converter; (24) Absolute Sound Recorder, Video to Audio Converter, and MP3 Splitter; (25) Easy Ringtone Maker; (26) RecordNRip; (27) McFunSoft iPod Audio Studio, Audio Recorder for Free, and others; (28) MP3 WAV Converter; (29) BearShare 6.0.2.26789; and (30) Oracle Siebel SimBuilder and CRM 7.x.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| altdo | convert_mp3_master | 1.1 | - | - |
cpe:2.3:a:altdo:convert_mp3_master:1.1:*:*:*:*:*:*:*
|
| altdo | mp3_record_and_edit_audio_master | 1.2 | - | - |
cpe:2.3:a:altdo:mp3_record_and_edit_audio_master:1.2:*:*:*:*:*:*:*
|
| americanshareware | mp3_wav_converter | 3.1.8 | - | - |
cpe:2.3:a:americanshareware:mp3_wav_converter:3.1.8:*:*:*:*:*:*:*
|
| audio_edit_magic | audio_edit_magic | 9.2.3_389 | - | - |
cpe:2.3:a:audio_edit_magic:audio_edit_magic:9.2.3_389:*:*:*:*:*:*:*
|
| bearshare | bearshare | 6.0.2.26789 | - | - |
cpe:2.3:a:bearshare:bearshare:6.0.2.26789:*:*:*:*:*:*:*
|
| cdburnerxp | cdburnerxp_pro | 3.0.116 | - | - |
cpe:2.3:a:cdburnerxp:cdburnerxp_pro:3.0.116:*:*:*:*:*:*:*
|
| cheetahburner | cheetah_cd_burner | 3.56 | - | - |
cpe:2.3:a:cheetahburner:cheetah_cd_burner:3.56:*:*:*:*:*:*:*
|
| cheetahburner | cheetah_dvd_burner | 1.79 | - | - |
cpe:2.3:a:cheetahburner:cheetah_dvd_burner:1.79:*:*:*:*:*:*:*
|
| code-it_softare | abasic_editor | 10.1 | - | - |
cpe:2.3:a:code-it_softare:abasic_editor:10.1:*:*:*:*:*:*:*
|
| code-it_softare | wave_mp3_editor | 10.1 | - | - |
cpe:2.3:a:code-it_softare:wave_mp3_editor:10.1:*:*:*:*:*:*:*
|
| dandans_digital_media_products | easy_audio_editor | 7.4 | - | - |
cpe:2.3:a:dandans_digital_media_products:easy_audio_editor:7.4:*:*:*:*:*:*:*
|
| dandans_digital_media_products | full_audio_converter | 4.2 | - | - |
cpe:2.3:a:dandans_digital_media_products:full_audio_converter:4.2:*:*:*:*:*:*:*
|
| dandans_digital_media_products | music_editing_master | 5.2 | - | - |
cpe:2.3:a:dandans_digital_media_products:music_editing_master:5.2:*:*:*:*:*:*:*
|
| dandans_digital_media_products | visual_video_converter | 4.4 | - | - |
cpe:2.3:a:dandans_digital_media_products:visual_video_converter:4.4:*:*:*:*:*:*:*
|
| digital_borneo | audio_mixer_and_editor | 1.1.0 | - | - |
cpe:2.3:a:digital_borneo:audio_mixer_and_editor:1.1.0:*:*:*:*:*:*:*
|
| easy_ringtone_maker | easy_ringtone_maker | 2.0.5 | - | - |
cpe:2.3:a:easy_ringtone_maker:easy_ringtone_maker:2.0.5:*:*:*:*:*:*:*
|
| expstudio | audio_editor | 4.0.2 | - | - |
cpe:2.3:a:expstudio:audio_editor:4.0.2:*:*:*:*:*:*:*
|
| iaudiosoft.com | absolute_mp3_splitter | 2.5.4 | - | - |
cpe:2.3:a:iaudiosoft.com:absolute_mp3_splitter:2.5.4:*:*:*:*:*:*:*
|
| iaudiosoft.com | absolute_sound_recorder | 3.4.5 | - | - |
cpe:2.3:a:iaudiosoft.com:absolute_sound_recorder:3.4.5:*:*:*:*:*:*:*
|
| iaudiosoft.com | absolute_video_to_audio_converter | 2.7.9 | - | - |
cpe:2.3:a:iaudiosoft.com:absolute_video_to_audio_converter:2.7.9:*:*:*:*:*:*:*
|
| imesh.com | imesh | 7.0.2.26789 | - | - |
cpe:2.3:a:imesh.com:imesh:7.0.2.26789:*:*:*:*:*:*:*
|
| j_hepple_products | fx_audio_concat | 1.2.0_beta | - | - |
cpe:2.3:a:j_hepple_products:fx_audio_concat:1.2.0_beta:*:*:*:*:*:*:*
|
| j_hepple_products | fx_audio_editor | 4.7.11 | - | - |
cpe:2.3:a:j_hepple_products:fx_audio_editor:4.7.11:*:*:*:*:*:*:*
|
| j_hepple_products | fx_audio_tools | 7.3.4 | - | - |
cpe:2.3:a:j_hepple_products:fx_audio_tools:7.3.4:*:*:*:*:*:*:*
|
| j_hepple_products | fx_magic_music | 5.7.7 | - | - |
cpe:2.3:a:j_hepple_products:fx_magic_music:5.7.7:*:*:*:*:*:*:*
|
| j_hepple_products | fx_movie_joiner | 6.2.8 | - | - |
cpe:2.3:a:j_hepple_products:fx_movie_joiner:6.2.8:*:*:*:*:*:*:*
|
| j_hepple_products | fx_movie_joiner_and_splitter | 6.2.8 | - | - |
cpe:2.3:a:j_hepple_products:fx_movie_joiner_and_splitter:6.2.8:*:*:*:*:*:*:*
|
| j_hepple_products | fx_movie_splitter | 6.4.7 | - | - |
cpe:2.3:a:j_hepple_products:fx_movie_splitter:6.4.7:*:*:*:*:*:*:*
|
| j_hepple_products | fx_new_sound | 5.1.1 | - | - |
cpe:2.3:a:j_hepple_products:fx_new_sound:5.1.1:*:*:*:*:*:*:*
|
| j_hepple_products | fx_video_converter | 7.51.21 | - | - |
cpe:2.3:a:j_hepple_products:fx_video_converter:7.51.21:*:*:*:*:*:*:*
|
| joshua_mediasoft | audio_convertor_plus | 2.2 | - | - |
cpe:2.3:a:joshua_mediasoft:audio_convertor_plus:2.2:*:*:*:*:*:*:*
|
| joshua_mediasoft | video_converter_plus | 3.01 | - | - |
cpe:2.3:a:joshua_mediasoft:video_converter_plus:3.01:*:*:*:*:*:*:*
|
| magicvideosoftare | magic_audio_converter | 8.2.6_build_719 | - | - |
cpe:2.3:a:magicvideosoftare:magic_audio_converter:8.2.6_build_719:*:*:*:*:*:*:*
|
| magicvideosoftare | magic_audio_recorder | 5.3.7 | - | - |
cpe:2.3:a:magicvideosoftare:magic_audio_recorder:5.3.7:*:*:*:*:*:*:*
|
| magicvideosoftare | magic_music_editor | 5.2.2 | - | - |
cpe:2.3:a:magicvideosoftare:magic_music_editor:5.2.2:*:*:*:*:*:*:*
|
| mcfunsoft | audio_editor | 6.3.3_build_489 | - | - |
cpe:2.3:a:mcfunsoft:audio_editor:6.3.3_build_489:*:*:*:*:*:*:*
|
| mcfunsoft | audio_recorder_for_free | 6.1 | - | - |
cpe:2.3:a:mcfunsoft:audio_recorder_for_free:6.1:*:*:*:*:*:*:*
|
| mcfunsoft | audio_studio | 6.6.3_build_479 | - | - |
cpe:2.3:a:mcfunsoft:audio_studio:6.6.3_build_479:*:*:*:*:*:*:*
|
| mcfunsoft | ipod_audio_studio | 6.2.4 | - | - |
cpe:2.3:a:mcfunsoft:ipod_audio_studio:6.2.4:*:*:*:*:*:*:*
|
| mcfunsoft | ipod_music_converter | 5.1 | - | - |
cpe:2.3:a:mcfunsoft:ipod_music_converter:5.1:*:*:*:*:*:*:*
|
| mcfunsoft | recording_to_ipod_solution | 5.1 | - | - |
cpe:2.3:a:mcfunsoft:recording_to_ipod_solution:5.1:*:*:*:*:*:*:*
|
| mediatox | aurora_media_workshop | 3.3.25 | - | - |
cpe:2.3:a:mediatox:aurora_media_workshop:3.3.25:*:*:*:*:*:*:*
|
| movavi | chiliburner | 2.3 | - | - |
cpe:2.3:a:movavi:chiliburner:2.3:*:*:*:*:*:*:*
|
| movavi | convertmovie | 4.4 | - | - |
cpe:2.3:a:movavi:convertmovie:4.4:*:*:*:*:*:*:*
|
| movavi | dvd_to_ipod | 1.0 | - | - |
cpe:2.3:a:movavi:dvd_to_ipod:1.0:*:*:*:*:*:*:*
|
| movavi | splitmovie | 1.4 | - | - |
cpe:2.3:a:movavi:splitmovie:1.4:*:*:*:*:*:*:*
|
| movavi | suite | 3.5 | - | - |
cpe:2.3:a:movavi:suite:3.5:*:*:*:*:*:*:*
|
| movavi | videomessage | 1.0 | - | - |
cpe:2.3:a:movavi:videomessage:1.0:*:*:*:*:*:*:*
|
| mp3-soft | mp3_normalizer | 1.03 | - | - |
cpe:2.3:a:mp3-soft:mp3_normalizer:1.03:*:*:*:*:*:*:*
|
| mystik_media_products | audioedit_deluxe | 4.10 | - | - |
cpe:2.3:a:mystik_media_products:audioedit_deluxe:4.10:*:*:*:*:*:*:*
|
| mystik_media_products | blaze_media_pro | 7.0 | - | - |
cpe:2.3:a:mystik_media_products:blaze_media_pro:7.0:*:*:*:*:*:*:*
|
| mystik_media_products | blaze_mediaconvert | 3.4 | - | - |
cpe:2.3:a:mystik_media_products:blaze_mediaconvert:3.4:*:*:*:*:*:*:*
|
| mystik_media_products | contextconvert_pro | 3.1 | - | - |
cpe:2.3:a:mystik_media_products:contextconvert_pro:3.1:*:*:*:*:*:*:*
|
| nctsoft_products | nctaudioeditor | 2.7.1 | - | - |
cpe:2.3:a:nctsoft_products:nctaudioeditor:2.7.1:*:*:*:*:*:*:*
|
| nctsoft_products | nctaudiofile2 | * | - | - |
cpe:2.3:a:nctsoft_products:nctaudiofile2:*:*:*:*:*:*:*:*
|
| nctsoft_products | nctaudiostudio | 2.7.1 | - | - |
cpe:2.3:a:nctsoft_products:nctaudiostudio:2.7.1:*:*:*:*:*:*:*
|
| nctsoft_products | nctdialogicvoice | 2.7.1 | - | - |
cpe:2.3:a:nctsoft_products:nctdialogicvoice:2.7.1:*:*:*:*:*:*:*
|
| nextlevel_systems | audio_editor_gold | 9.2.5_build_424 | - | - |
cpe:2.3:a:nextlevel_systems:audio_editor_gold:9.2.5_build_424:*:*:*:*:*:*:*
|
| nextlevel_systems | audio_studio_gold | 7.0.1.1_build_500 | - | - |
cpe:2.3:a:nextlevel_systems:audio_studio_gold:7.0.1.1_build_500:*:*:*:*:*:*:*
|
| quikscribe | quikscribe_player | 5.022.05 | - | - |
cpe:2.3:a:quikscribe:quikscribe_player:5.022.05:*:*:*:*:*:*:*
|
| quikscribe | quikscribe_recorder | 5.021.29 | - | - |
cpe:2.3:a:quikscribe:quikscribe_recorder:5.021.29:*:*:*:*:*:*:*
|
| recordnrip | recordnrip | 1.0 | - | - |
cpe:2.3:a:recordnrip:recordnrip:1.0:*:*:*:*:*:*:*
|
| rmbsoft | audioconvert | 3.1.0.125 | - | - |
cpe:2.3:a:rmbsoft:audioconvert:3.1.0.125:*:*:*:*:*:*:*
|
| rmbsoft | soundedit_pro | 2.1 | - | - |
cpe:2.3:a:rmbsoft:soundedit_pro:2.1:*:*:*:*:*:*:*
|
| roemer_software | easy_hi-q_converter | 1.7 | - | - |
cpe:2.3:a:roemer_software:easy_hi-q_converter:1.7:*:*:*:*:*:*:*
|
| roemer_software | easy_hi-q_recorder | 2.0 | - | - |
cpe:2.3:a:roemer_software:easy_hi-q_recorder:2.0:*:*:*:*:*:*:*
|
| roemer_software | free_hi-q_recorder | 1.9 | - | - |
cpe:2.3:a:roemer_software:free_hi-q_recorder:1.9:*:*:*:*:*:*:*
|
| sienzo | digital_music_mentor | 2.6.0.3 | - | - |
cpe:2.3:a:sienzo:digital_music_mentor:2.6.0.3:*:*:*:*:*:*:*
|
| smart_media_systems | power_audio_editor | 11.0.1 | - | - |
cpe:2.3:a:smart_media_systems:power_audio_editor:11.0.1:*:*:*:*:*:*:*
|
| softdiv_softare | dexster | 3.0 | - | - |
cpe:2.3:a:softdiv_softare:dexster:3.0:*:*:*:*:*:*:*
|
| softdiv_softare | ivideomax | 3.9 | - | - |
cpe:2.3:a:softdiv_softare:ivideomax:3.9:*:*:*:*:*:*:*
|
| softdiv_softare | mp3_to_wav_converter | 3.0 | - | - |
cpe:2.3:a:softdiv_softare:mp3_to_wav_converter:3.0:*:*:*:*:*:*:*
|
| softdiv_softare | snosh | 1.4 | - | - |
cpe:2.3:a:softdiv_softare:snosh:1.4:*:*:*:*:*:*:*
|
| softdiv_softare | videozilla | 2.5 | - | - |
cpe:2.3:a:softdiv_softare:videozilla:2.5:*:*:*:*:*:*:*
|
| virtual_cd | virtual_cd | 6.0.0.7 | - | - |
cpe:2.3:a:virtual_cd:virtual_cd:6.0.0.7:*:*:*:*:*:*:*
|
| virtual_cd | virtual_cd | 7.1.0.2 | - | - |
cpe:2.3:a:virtual_cd:virtual_cd:7.1.0.2:*:*:*:*:*:*:*
|
| virtual_cd | virtual_cd | 8.0.0.6 | - | - |
cpe:2.3:a:virtual_cd:virtual_cd:8.0.0.6:*:*:*:*:*:*:*
|
| virtual_cd | virtual_cd_file_server | 7.1.0.3 | - | - |
cpe:2.3:a:virtual_cd:virtual_cd_file_server:7.1.0.3:*:*:*:*:*:*:*
|
| xrlly_software | arial_audio_converter | 2.3.40 | - | - |
cpe:2.3:a:xrlly_software:arial_audio_converter:2.3.40:*:*:*:*:*:*:*
|
| xrlly_software | arial_sound_recorder | 1.4.3 | - | - |
cpe:2.3:a:xrlly_software:arial_sound_recorder:1.4.3:*:*:*:*:*:*:*
|
| xrlly_software | text_to_speech_maker | 1.3.8 | - | - |
cpe:2.3:a:xrlly_software:text_to_speech_maker:1.3.8:*:*:*:*:*:*:*
|
| xwaver.com | magic_audio_editor_pro | 10.3.1_build_476 | - | - |
cpe:2.3:a:xwaver.com:magic_audio_editor_pro:10.3.1_build_476:*:*:*:*:*:*:*
|
| xwaver.com | magic_music_studio_pro | 7.0.2.1_build_500 | - | - |
cpe:2.3:a:xwaver.com:magic_music_studio_pro:7.0.2.1_build_500:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
exploitdb
exploitdb
cve.org
exploitdb
exploitdb
exploitdb
exploitdb
CVSS评分详情
AV:N/AC:M/Au:N/C:C/I:C/A:C
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2007-0018 |
2025-11-11 15:17:48 | 2025-11-11 07:32:40 |
| NVD | nvd_CVE-2007-0018 |
2025-11-11 14:52:08 | 2025-11-11 07:41:26 |
| CNNVD | cnnvd_CNNVD-200701-427 |
2025-11-11 15:08:55 | 2025-11-11 07:49:14 |
| EXPLOITDB | exploitdb_EDB-16603 |
2025-11-11 15:05:57 | 2025-11-11 08:11:04 |
| EXPLOITDB | exploitdb_EDB-3728 |
2025-11-11 15:05:56 | 2025-11-11 08:34:30 |
| EXPLOITDB | exploitdb_EDB-3808 |
2025-11-11 15:05:56 | 2025-11-11 08:36:04 |
版本与语言
安全公告
变更历史
查看详细变更
- references_count: 93 -> 95
- tags_count: 5 -> 6
查看详细变更
- references_count: 91 -> 93
- tags_count: 4 -> 5
查看详细变更
- references_count: 88 -> 91
- tags_count: 0 -> 4
- data_sources: ['cnnvd', 'cve', 'nvd'] -> ['cnnvd', 'cve', 'exploitdb', 'nvd']
查看详细变更
- vulnerability_type: 未提取 -> 授权问题
- cnnvd_id: 未提取 -> CNNVD-200701-427
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.CRITICAL
- cvss_score: 未提取 -> 9.3
- cvss_vector: NOT_EXTRACTED -> AV:N/AC:M/Au:N/C:C/I:C/A:C
- cvss_version: NOT_EXTRACTED -> 2.0
- affected_products_count: 0 -> 83
- data_sources: ['cve'] -> ['cve', 'nvd']