Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function
Published Jan 24, 2007
9.3
HIGHCVSS 2.0
EPSS 36.47%
Description
Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. NOTE: the products include (1) NCTsoft NCTAudioStudio, NCTAudioEditor, and NCTDialogicVoice; (2) Magic Audio Recorder, Music Editor, and Audio Converter; (3) Aurora Media Workshop; DB Audio Mixer And Editor; (4) J. Hepple Products including Fx Audio Editor and others; (5) EXPStudio Audio Editor; (6) iMesh; (7) Quikscribe; (8) RMBSoft AudioConvert and SoundEdit Pro 2.1; (9) CDBurnerXP; (10) Code-it Software Wave MP3 Editor and aBasic Editor; (11) Movavi VideoMessage, DVD to iPod, and others; (12) SoftDiv Software Dexster, iVideoMAX, and others; (13) Sienzo Digital Music Mentor (DMM); (14) MP3 Normalizer; (15) Roemer Software FREE and Easy Hi-Q Recorder, and Easy Hi-Q Converter; (16) Audio Edit Magic; (17) Joshua Video and Audio Converter; (18) Virtual CD; (19) Cheetah CD and DVD Burner; (20) Mystik Media AudioEdit Deluxe, Blaze Media, and others; (21) Power Audio Editor; (22) DanDans Digital Media Full Audio Converter, Music Editing Master, and others; (23) Xrlly Software Text to Speech Makerand Arial Sound Recorder / Audio Converter; (24) Absolute Sound Recorder, Video to Audio Converter, and MP3 Splitter; (25) Easy Ringtone Maker; (26) RecordNRip; (27) McFunSoft iPod Audio Studio, Audio Recorder for Free, and others; (28) MP3 WAV Converter; (29) BearShare 6.0.2.26789; and (30) Oracle Siebel SimBuilder and CRM 7.x.
Affected products
No data.
- 1.1
- 1.2
- 3.1.8
- 9.2.3_389
- 6.0.2.26789
- 3.0.116
- 3.56
- 1.79
- 10.1
- 10.1
- 7.4
- 4.2
- 5.2
- 4.4
- 1.1.0
- 2.0.5
- 4.0.2
- 2.5.4
- 3.4.5
- 2.7.9
- 7.0.2.26789
- 1.2.0_beta
- 4.7.11
- 7.3.4
- 5.7.7
- 6.2.8
- 6.2.8
- 6.4.7
- 5.1.1
- 7.51.21
- 2.2
- 3.01
- 8.2.6_build_719
- 5.3.7
- 5.2.2
- 6.3.3_build_489
- 6.1
- 6.6.3_build_479
- 6.2.4
- 5.1
- 5.1
- 3.3.25
- 2.3
- 4.4
- 1.0
- 1.4
- 3.5
- 1.0
- 1.03
- 4.10
- 7.0
- 3.4
- 3.1
- 2.7.1
- n/a
- 2.7.1
- 2.7.1
- 9.2.5_build_424
- 7.0.1.1_build_500
- 5.022.05
- 5.021.29
- 1.0
- 3.1.0.125
- 2.1
- 1.7
- 2.0
- 1.9
- 2.6.0.3
- 11.0.1
- 3.0
- 3.9
- 3.0
- 1.4
- 2.5
- 6.0.0.7
- 7.1.0.2
- 8.0.0.6
- 7.1.0.3
- 2.3.40
- 1.4.3
- 1.3.8
- 10.3.1_build_476
- 7.0.2.1_build_500
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (25 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 36.47% (0.36473) | 98.45th | v5 (v2026.06.15) |
| Aug 22, 2026 | 36.47% (0.36473) | 98.37th | v5 (v2026.06.15) |
| Jun 15, 2026 | 35.16% (0.35162) | 98.23th | v5 (v2026.06.15) |
| May 3, 2026 | 73.81% (0.73809) | 98.83th | v4 (v2025.03.14) |
| Mar 30, 2026 | 79.26% (0.79259) | 99.06th | v4 (v2025.03.14) |
| Mar 10, 2026 | 77.60% (0.77601) | 98.97th | v4 (v2025.03.14) |
| Feb 18, 2026 | 80.88% (0.80885) | 99.12th | v4 (v2025.03.14) |
| Jan 13, 2026 | 78.02% (0.78024) | 98.96th | v4 (v2025.03.14) |
| Nov 4, 2025 | 74.57% (0.74574) | 98.79th | v4 (v2025.03.14) |
| Sep 12, 2025 | 72.47% (0.72473) | 98.72th | v4 (v2025.03.14) |
| Jul 26, 2025 | 70.10% (0.70100) | 98.59th | v4 (v2025.03.14) |
| May 3, 2025 | 74.97% (0.74968) | 98.80th | v4 (v2025.03.14) |
| Mar 30, 2025 | 70.10% (0.70100) | 98.56th | v4 (v2025.03.14) |
| Mar 29, 2025 | 71.12% (0.71118) | 98.27th | v4 (v2025.03.14) |
| Mar 17, 2025 | 69.28% (0.69280) | 98.54th | v4 (v2025.03.14) |
| Dec 17, 2024 | 89.43% (0.89429) | 99.00th | v3 (v2023.03.01) |
| Mar 21, 2024 | 95.21% (0.95209) | 99.28th | v3 (v2023.03.01) |
| Feb 12, 2024 | 94.85% (0.94849) | 99.19th | v3 (v2023.03.01) |
| Nov 28, 2023 | 95.21% (0.95209) | 99.15th | v3 (v2023.03.01) |
| Oct 21, 2023 | 95.65% (0.95646) | 99.20th | v3 (v2023.03.01) |
| Jun 28, 2023 | 95.33% (0.95325) | 99.02th | v3 (v2023.03.01) |
| Apr 15, 2023 | 95.27% (0.95265) | 98.92th | v3 (v2023.03.01) |
| Mar 7, 2023 | 94.67% (0.94674) | 98.72th | v3 (v2023.03.01) |
| Mar 6, 2023 | 80.73% (0.80730) | 99.52th | v2 (v2022.01.01) |
| Feb 4, 2022 | 80.73% (0.80730) | 99.43th | v2 (v2022.01.01) |
References (88)
- http://secunia.com/advisories/22922 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23475 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23485 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23493 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23495 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23511 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23516 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23530 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23532 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23534 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23535 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23536 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23541 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23542 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23543 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23544 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23546 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23548 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23550 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23551 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23552 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23553 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23554 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23557 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23558 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23560 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23561 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23562 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23565 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23568 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23745 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23753 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23795 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/25993 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/26046 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/26100 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/26101 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/28407 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30406 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30424 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30439 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30446 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30447 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30450 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30459 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/blog/6/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-10/advisory/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-11/advisory/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-12/advisory/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-13/advisory/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-14/advisory/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-15/advisory/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-16/advisory/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-17/advisory/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-18/advisory/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-19/advisory/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-2/advisory/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-20/advisory/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-21/advisory/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-22/advisory/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-23/advisory/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-24/advisory/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-25/advisory/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-26/advisory/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-27/advisory/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-28/advisory/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-29/advisory/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-3/advisory/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-30/advisory/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-31/advisory/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-32/advisory/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-33/advisory/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-34/advisory/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-4/advisory/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-5/advisory/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-50/advisory/ x_refsource_MISC
- http://secunia.com/secunia_research/2007-6/advisory/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-7/advisory/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-8/advisory/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2007-9/advisory/ x_refsource_MISCVendor Advisory
- http://www.kb.cert.org/vuls/id/292713 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.securityfocus.com/archive/1/457936/100/200/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/457940/100/200/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/457965/100/200/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/22196 vdb-entryx_refsource_BID
- http://www.securityfocus.com/bid/23892 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2007/0310 vdb-entryx_refsource_VUPEN
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31707 vdb-entryx_refsource_XF
Change history (0)
No recorded changes yet.