CVE-2007-0018

Exp

Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. NOTE: the products include (1) NCTsoft NCTAudioStudio, NCTAudioEditor, and NCTDialogicVoice; (2) Magic Audio Recorder, Music Editor, and Audio Converter; (3) Aurora Media Workshop; DB Audio Mixer And Editor; (4) J. Hepple Products including Fx Audio Editor and others; (5) EXPStudio Audio Editor; (6) iMesh; (7) Quikscribe; (8) RMBSoft AudioConvert and SoundEdit Pro 2.1; (9) CDBurnerXP; (10) Code-it Software Wave MP3 Editor and aBasic Editor; (11) Movavi VideoMessage, DVD to iPod, and others; (12) SoftDiv Software Dexster, iVideoMAX, and others; (13) Sienzo Digital Music Mentor (DMM); (14) MP3 Normalizer; (15) Roemer Software FREE and Easy Hi-Q Recorder, and Easy Hi-Q Converter; (16) Audio Edit Magic; (17) Joshua Video and Audio Converter; (18) Virtual CD; (19) Cheetah CD and DVD Burner; (20) Mystik Media AudioEdit Deluxe, Blaze Media, and others; (21) Power Audio Editor; (22) DanDans Digital Media Full Audio Converter, Music Editing Master, and others; (23) Xrlly Software Text to Speech Makerand Arial Sound Recorder / Audio Converter; (24) Absolute Sound Recorder, Video to Audio Converter, and MP3 Splitter; (25) Easy Ringtone Maker; (26) RecordNRip; (27) McFunSoft iPod Audio Studio, Audio Recorder for Free, and others; (28) MP3 WAV Converter; (29) BearShare 6.0.2.26789; and (30) Oracle Siebel SimBuilder and CRM 7.x.

公開: 2007-01-24 最終更新: 2026-04-23 Assigner: [email protected] ソース: [email protected]

総合評価: CVE-2007-0018 は悪用リスクが高い(81.8/100)。CVSS 深刻度は重大。悪用される可能性が高い(EPSS 73.81%、99 パーセンタイル) 根拠: 公開エクスプロイトが 3 件参照されています(Exploit-DB)。 推奨対応: 公開エクスプロイトが確認されています。影響範囲の確認、緩和策の適用、パッチ適用を優先してください。

リスクは変動します。再評価に基づき、本ページの表示内容を更新しています。

CVE-2007-0018 に関する公開 exploit 参照(Exploit-DB)

EDB-ID ソース 種別 公開 リンク
16603 exploit_db edb 2010-07-03 Exploit-DB ↗
3808 exploit_db edb 2007-04-27 Exploit-DB ↗
3728 exploit_db edb 2007-04-13 Exploit-DB ↗

CVE-2007-0018 の EPSS(Exploit Prediction Scoring System)スコア

EPSS は日次で悪用されやすさの相対度合いを推定します。パーセンタイルは採点済み CVE の中での相対位置(高いほど相対的に深刻)を示します。

# 日付 旧 EPSS スコア 新 EPSS スコア Δ(新 − 旧)
1 2026-05-03 79.26% 73.81% -5.45%
2 2026-03-30 77.60% 79.26% +1.66%
3 2026-03-10 77.60%

EPSS の全履歴 (全 23 件)

CVE-2007-0018 の CVSS(Common Vulnerability Scoring System)指標

この CVE の CVSS 指標。

ベーススコア バージョン 深刻度 ベクトル 悪用しやすさ 影響 スコアの出典
9.3 2.0 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C クリックして展開
アクセス経路 (AV:N)
ルーティング可能なネットワーク越しに、遠隔から到達・悪用しうる。
アクセスの複雑さ (AC:M)
多少の有利条件は要るが、極端なレアケースではない。
認証 (AU:N)
認証を経ずに攻撃を完結できる。
機密性への影響 (C:C)
機密性は全面的に損なわれる。
完全性への影響 (I:C)
完全性は全面的に損なわれる。
可用性への影響 (A:C)
可用性は全面的に損なわれる。
8.6 10.0 [email protected]

CVE-2007-0018 の弱点分類(列挙)

CVE-2007-0018 の影響を受けるソフトウェア/構成

ベンダー 製品 バージョン 生の CPE
altdo convert_mp3_master 1.1 cpe:2.3:a:altdo:convert_mp3_master:1.1:*:*:*:*:*:*:*
altdo mp3_record_and_edit_audio_master 1.2 cpe:2.3:a:altdo:mp3_record_and_edit_audio_master:1.2:*:*:*:*:*:*:*
americanshareware mp3_wav_converter 3.1.8 cpe:2.3:a:americanshareware:mp3_wav_converter:3.1.8:*:*:*:*:*:*:*
audio_edit_magic audio_edit_magic 9.2.3_389 cpe:2.3:a:audio_edit_magic:audio_edit_magic:9.2.3_389:*:*:*:*:*:*:*
bearshare bearshare 6.0.2.26789 cpe:2.3:a:bearshare:bearshare:6.0.2.26789:*:*:*:*:*:*:*
cdburnerxp cdburnerxp_pro 3.0.116 cpe:2.3:a:cdburnerxp:cdburnerxp_pro:3.0.116:*:*:*:*:*:*:*
cheetahburner cheetah_cd_burner 3.56 cpe:2.3:a:cheetahburner:cheetah_cd_burner:3.56:*:*:*:*:*:*:*
cheetahburner cheetah_dvd_burner 1.79 cpe:2.3:a:cheetahburner:cheetah_dvd_burner:1.79:*:*:*:*:*:*:*
code-it_softare abasic_editor 10.1 cpe:2.3:a:code-it_softare:abasic_editor:10.1:*:*:*:*:*:*:*
code-it_softare wave_mp3_editor 10.1 cpe:2.3:a:code-it_softare:wave_mp3_editor:10.1:*:*:*:*:*:*:*
dandans_digital_media_products easy_audio_editor 7.4 cpe:2.3:a:dandans_digital_media_products:easy_audio_editor:7.4:*:*:*:*:*:*:*
dandans_digital_media_products full_audio_converter 4.2 cpe:2.3:a:dandans_digital_media_products:full_audio_converter:4.2:*:*:*:*:*:*:*
dandans_digital_media_products music_editing_master 5.2 cpe:2.3:a:dandans_digital_media_products:music_editing_master:5.2:*:*:*:*:*:*:*
dandans_digital_media_products visual_video_converter 4.4 cpe:2.3:a:dandans_digital_media_products:visual_video_converter:4.4:*:*:*:*:*:*:*
digital_borneo audio_mixer_and_editor 1.1.0 cpe:2.3:a:digital_borneo:audio_mixer_and_editor:1.1.0:*:*:*:*:*:*:*
easy_ringtone_maker easy_ringtone_maker 2.0.5 cpe:2.3:a:easy_ringtone_maker:easy_ringtone_maker:2.0.5:*:*:*:*:*:*:*
expstudio audio_editor 4.0.2 cpe:2.3:a:expstudio:audio_editor:4.0.2:*:*:*:*:*:*:*
iaudiosoft.com absolute_mp3_splitter 2.5.4 cpe:2.3:a:iaudiosoft.com:absolute_mp3_splitter:2.5.4:*:*:*:*:*:*:*
iaudiosoft.com absolute_sound_recorder 3.4.5 cpe:2.3:a:iaudiosoft.com:absolute_sound_recorder:3.4.5:*:*:*:*:*:*:*
iaudiosoft.com absolute_video_to_audio_converter 2.7.9 cpe:2.3:a:iaudiosoft.com:absolute_video_to_audio_converter:2.7.9:*:*:*:*:*:*:*
imesh.com imesh 7.0.2.26789 cpe:2.3:a:imesh.com:imesh:7.0.2.26789:*:*:*:*:*:*:*
j_hepple_products fx_audio_concat 1.2.0_beta cpe:2.3:a:j_hepple_products:fx_audio_concat:1.2.0_beta:*:*:*:*:*:*:*
j_hepple_products fx_audio_editor 4.7.11 cpe:2.3:a:j_hepple_products:fx_audio_editor:4.7.11:*:*:*:*:*:*:*
j_hepple_products fx_audio_tools 7.3.4 cpe:2.3:a:j_hepple_products:fx_audio_tools:7.3.4:*:*:*:*:*:*:*
j_hepple_products fx_magic_music 5.7.7 cpe:2.3:a:j_hepple_products:fx_magic_music:5.7.7:*:*:*:*:*:*:*
j_hepple_products fx_movie_joiner 6.2.8 cpe:2.3:a:j_hepple_products:fx_movie_joiner:6.2.8:*:*:*:*:*:*:*
j_hepple_products fx_movie_joiner_and_splitter 6.2.8 cpe:2.3:a:j_hepple_products:fx_movie_joiner_and_splitter:6.2.8:*:*:*:*:*:*:*
j_hepple_products fx_movie_splitter 6.4.7 cpe:2.3:a:j_hepple_products:fx_movie_splitter:6.4.7:*:*:*:*:*:*:*
j_hepple_products fx_new_sound 5.1.1 cpe:2.3:a:j_hepple_products:fx_new_sound:5.1.1:*:*:*:*:*:*:*
j_hepple_products fx_video_converter 7.51.21 cpe:2.3:a:j_hepple_products:fx_video_converter:7.51.21:*:*:*:*:*:*:*
joshua_mediasoft audio_convertor_plus 2.2 cpe:2.3:a:joshua_mediasoft:audio_convertor_plus:2.2:*:*:*:*:*:*:*
joshua_mediasoft video_converter_plus 3.01 cpe:2.3:a:joshua_mediasoft:video_converter_plus:3.01:*:*:*:*:*:*:*
magicvideosoftare magic_audio_converter 8.2.6_build_719 cpe:2.3:a:magicvideosoftare:magic_audio_converter:8.2.6_build_719:*:*:*:*:*:*:*
magicvideosoftare magic_audio_recorder 5.3.7 cpe:2.3:a:magicvideosoftare:magic_audio_recorder:5.3.7:*:*:*:*:*:*:*
magicvideosoftare magic_music_editor 5.2.2 cpe:2.3:a:magicvideosoftare:magic_music_editor:5.2.2:*:*:*:*:*:*:*
mcfunsoft audio_editor 6.3.3_build_489 cpe:2.3:a:mcfunsoft:audio_editor:6.3.3_build_489:*:*:*:*:*:*:*
mcfunsoft audio_recorder_for_free 6.1 cpe:2.3:a:mcfunsoft:audio_recorder_for_free:6.1:*:*:*:*:*:*:*
mcfunsoft audio_studio 6.6.3_build_479 cpe:2.3:a:mcfunsoft:audio_studio:6.6.3_build_479:*:*:*:*:*:*:*
mcfunsoft ipod_audio_studio 6.2.4 cpe:2.3:a:mcfunsoft:ipod_audio_studio:6.2.4:*:*:*:*:*:*:*
mcfunsoft ipod_music_converter 5.1 cpe:2.3:a:mcfunsoft:ipod_music_converter:5.1:*:*:*:*:*:*:*
mcfunsoft recording_to_ipod_solution 5.1 cpe:2.3:a:mcfunsoft:recording_to_ipod_solution:5.1:*:*:*:*:*:*:*
mediatox aurora_media_workshop 3.3.25 cpe:2.3:a:mediatox:aurora_media_workshop:3.3.25:*:*:*:*:*:*:*
movavi chiliburner 2.3 cpe:2.3:a:movavi:chiliburner:2.3:*:*:*:*:*:*:*
movavi convertmovie 4.4 cpe:2.3:a:movavi:convertmovie:4.4:*:*:*:*:*:*:*
movavi dvd_to_ipod 1.0 cpe:2.3:a:movavi:dvd_to_ipod:1.0:*:*:*:*:*:*:*
movavi splitmovie 1.4 cpe:2.3:a:movavi:splitmovie:1.4:*:*:*:*:*:*:*
movavi suite 3.5 cpe:2.3:a:movavi:suite:3.5:*:*:*:*:*:*:*
movavi videomessage 1.0 cpe:2.3:a:movavi:videomessage:1.0:*:*:*:*:*:*:*
mp3-soft mp3_normalizer 1.03 cpe:2.3:a:mp3-soft:mp3_normalizer:1.03:*:*:*:*:*:*:*
mystik_media_products audioedit_deluxe 4.10 cpe:2.3:a:mystik_media_products:audioedit_deluxe:4.10:*:*:*:*:*:*:*
mystik_media_products blaze_media_pro 7.0 cpe:2.3:a:mystik_media_products:blaze_media_pro:7.0:*:*:*:*:*:*:*
mystik_media_products blaze_mediaconvert 3.4 cpe:2.3:a:mystik_media_products:blaze_mediaconvert:3.4:*:*:*:*:*:*:*
mystik_media_products contextconvert_pro 3.1 cpe:2.3:a:mystik_media_products:contextconvert_pro:3.1:*:*:*:*:*:*:*
nctsoft_products nctaudioeditor 2.7.1 cpe:2.3:a:nctsoft_products:nctaudioeditor:2.7.1:*:*:*:*:*:*:*
nctsoft_products nctaudiofile2 cpe:2.3:a:nctsoft_products:nctaudiofile2:*:*:*:*:*:*:*:*
nctsoft_products nctaudiostudio 2.7.1 cpe:2.3:a:nctsoft_products:nctaudiostudio:2.7.1:*:*:*:*:*:*:*
nctsoft_products nctdialogicvoice 2.7.1 cpe:2.3:a:nctsoft_products:nctdialogicvoice:2.7.1:*:*:*:*:*:*:*
nextlevel_systems audio_editor_gold 9.2.5_build_424 cpe:2.3:a:nextlevel_systems:audio_editor_gold:9.2.5_build_424:*:*:*:*:*:*:*
nextlevel_systems audio_studio_gold 7.0.1.1_build_500 cpe:2.3:a:nextlevel_systems:audio_studio_gold:7.0.1.1_build_500:*:*:*:*:*:*:*
quikscribe quikscribe_player 5.022.05 cpe:2.3:a:quikscribe:quikscribe_player:5.022.05:*:*:*:*:*:*:*
quikscribe quikscribe_recorder 5.021.29 cpe:2.3:a:quikscribe:quikscribe_recorder:5.021.29:*:*:*:*:*:*:*
recordnrip recordnrip 1.0 cpe:2.3:a:recordnrip:recordnrip:1.0:*:*:*:*:*:*:*
rmbsoft audioconvert 3.1.0.125 cpe:2.3:a:rmbsoft:audioconvert:3.1.0.125:*:*:*:*:*:*:*
rmbsoft soundedit_pro 2.1 cpe:2.3:a:rmbsoft:soundedit_pro:2.1:*:*:*:*:*:*:*
roemer_software easy_hi-q_converter 1.7 cpe:2.3:a:roemer_software:easy_hi-q_converter:1.7:*:*:*:*:*:*:*
roemer_software easy_hi-q_recorder 2.0 cpe:2.3:a:roemer_software:easy_hi-q_recorder:2.0:*:*:*:*:*:*:*
roemer_software free_hi-q_recorder 1.9 cpe:2.3:a:roemer_software:free_hi-q_recorder:1.9:*:*:*:*:*:*:*
sienzo digital_music_mentor 2.6.0.3 cpe:2.3:a:sienzo:digital_music_mentor:2.6.0.3:*:*:*:*:*:*:*
smart_media_systems power_audio_editor 11.0.1 cpe:2.3:a:smart_media_systems:power_audio_editor:11.0.1:*:*:*:*:*:*:*
softdiv_softare dexster 3.0 cpe:2.3:a:softdiv_softare:dexster:3.0:*:*:*:*:*:*:*
softdiv_softare ivideomax 3.9 cpe:2.3:a:softdiv_softare:ivideomax:3.9:*:*:*:*:*:*:*
softdiv_softare mp3_to_wav_converter 3.0 cpe:2.3:a:softdiv_softare:mp3_to_wav_converter:3.0:*:*:*:*:*:*:*
softdiv_softare snosh 1.4 cpe:2.3:a:softdiv_softare:snosh:1.4:*:*:*:*:*:*:*
softdiv_softare videozilla 2.5 cpe:2.3:a:softdiv_softare:videozilla:2.5:*:*:*:*:*:*:*
virtual_cd virtual_cd 6.0.0.7 cpe:2.3:a:virtual_cd:virtual_cd:6.0.0.7:*:*:*:*:*:*:*
virtual_cd virtual_cd 7.1.0.2 cpe:2.3:a:virtual_cd:virtual_cd:7.1.0.2:*:*:*:*:*:*:*
virtual_cd virtual_cd 8.0.0.6 cpe:2.3:a:virtual_cd:virtual_cd:8.0.0.6:*:*:*:*:*:*:*
virtual_cd virtual_cd_file_server 7.1.0.3 cpe:2.3:a:virtual_cd:virtual_cd_file_server:7.1.0.3:*:*:*:*:*:*:*
xrlly_software arial_audio_converter 2.3.40 cpe:2.3:a:xrlly_software:arial_audio_converter:2.3.40:*:*:*:*:*:*:*
xrlly_software arial_sound_recorder 1.4.3 cpe:2.3:a:xrlly_software:arial_sound_recorder:1.4.3:*:*:*:*:*:*:*

CVE-2007-0018 の参考情報

URL タグ
http://secunia.com/advisories/22922
http://secunia.com/advisories/23475 Vendor Advisory
http://secunia.com/advisories/23485 Vendor Advisory
http://secunia.com/advisories/23493 Vendor Advisory
http://secunia.com/advisories/23495 Vendor Advisory
http://secunia.com/advisories/23511 Vendor Advisory
http://secunia.com/advisories/23516 Vendor Advisory
http://secunia.com/advisories/23530 Vendor Advisory
http://secunia.com/advisories/23532 Vendor Advisory
http://secunia.com/advisories/23534 Vendor Advisory
http://secunia.com/advisories/23535
http://secunia.com/advisories/23536
http://secunia.com/advisories/23541
http://secunia.com/advisories/23542
http://secunia.com/advisories/23543 Vendor Advisory
http://secunia.com/advisories/23544
http://secunia.com/advisories/23546
http://secunia.com/advisories/23548
http://secunia.com/advisories/23550
http://secunia.com/advisories/23551 Vendor Advisory
http://secunia.com/advisories/23552 Vendor Advisory
http://secunia.com/advisories/23553 Vendor Advisory
http://secunia.com/advisories/23554
http://secunia.com/advisories/23557 Vendor Advisory
http://secunia.com/advisories/23558
http://secunia.com/advisories/23560
http://secunia.com/advisories/23561
http://secunia.com/advisories/23562
http://secunia.com/advisories/23565
http://secunia.com/advisories/23568 Vendor Advisory
http://secunia.com/advisories/23745
http://secunia.com/advisories/23753
http://secunia.com/advisories/23795
http://secunia.com/advisories/25993
http://secunia.com/advisories/26046
http://secunia.com/advisories/26100
http://secunia.com/advisories/26101
http://secunia.com/advisories/28407
http://secunia.com/advisories/30406
http://secunia.com/advisories/30424
http://secunia.com/advisories/30439
http://secunia.com/advisories/30446
http://secunia.com/advisories/30447
http://secunia.com/advisories/30450
http://secunia.com/advisories/30459
http://secunia.com/blog/6/ Vendor Advisory
http://secunia.com/secunia_research/2007-10/advisory/ Vendor Advisory
http://secunia.com/secunia_research/2007-11/advisory/ Vendor Advisory
http://secunia.com/secunia_research/2007-12/advisory/ Vendor Advisory
http://secunia.com/secunia_research/2007-13/advisory/ Vendor Advisory
http://secunia.com/secunia_research/2007-14/advisory/ Vendor Advisory
http://secunia.com/secunia_research/2007-15/advisory/ Vendor Advisory
http://secunia.com/secunia_research/2007-16/advisory/ Vendor Advisory
http://secunia.com/secunia_research/2007-17/advisory/ Vendor Advisory
http://secunia.com/secunia_research/2007-18/advisory/ Vendor Advisory
http://secunia.com/secunia_research/2007-19/advisory/ Vendor Advisory
http://secunia.com/secunia_research/2007-2/advisory/ Vendor Advisory
http://secunia.com/secunia_research/2007-20/advisory/ Vendor Advisory
http://secunia.com/secunia_research/2007-21/advisory/ Vendor Advisory
http://secunia.com/secunia_research/2007-22/advisory/ Vendor Advisory
http://secunia.com/secunia_research/2007-23/advisory/ Vendor Advisory
http://secunia.com/secunia_research/2007-24/advisory/ Vendor Advisory
http://secunia.com/secunia_research/2007-25/advisory/ Vendor Advisory
http://secunia.com/secunia_research/2007-26/advisory/ Vendor Advisory
http://secunia.com/secunia_research/2007-27/advisory/ Vendor Advisory
http://secunia.com/secunia_research/2007-28/advisory/ Vendor Advisory
http://secunia.com/secunia_research/2007-29/advisory/ Vendor Advisory
http://secunia.com/secunia_research/2007-3/advisory/ Vendor Advisory
http://secunia.com/secunia_research/2007-30/advisory/ Vendor Advisory
http://secunia.com/secunia_research/2007-31/advisory/ Vendor Advisory
http://secunia.com/secunia_research/2007-32/advisory/ Vendor Advisory
http://secunia.com/secunia_research/2007-33/advisory/ Vendor Advisory
http://secunia.com/secunia_research/2007-34/advisory/ Vendor Advisory
http://secunia.com/secunia_research/2007-4/advisory/ Vendor Advisory
http://secunia.com/secunia_research/2007-5/advisory/ Vendor Advisory
http://secunia.com/secunia_research/2007-50/advisory/
http://secunia.com/secunia_research/2007-6/advisory/ Vendor Advisory
http://secunia.com/secunia_research/2007-7/advisory/ Vendor Advisory
http://secunia.com/secunia_research/2007-8/advisory/ Vendor Advisory
http://secunia.com/secunia_research/2007-9/advisory/ Vendor Advisory
http://www.kb.cert.org/vuls/id/292713 US Government Resource
http://www.securityfocus.com/archive/1/457936/100/200/threaded
http://www.securityfocus.com/archive/1/457940/100/200/threaded
http://www.securityfocus.com/archive/1/457965/100/200/threaded
http://www.securityfocus.com/bid/22196
http://www.securityfocus.com/bid/23892
http://www.vupen.com/english/advisories/2007/0310
https://exchange.xforce.ibmcloud.com/vulnerabilities/31707
cvelogic Threat Intelligence