{"api_version":"1","generated_at":"2026-07-23T08:08:39+00:00","cve":"CVE-2007-0163","urls":{"html":"https://cve.report/CVE-2007-0163","api":"https://cve.report/api/cve/CVE-2007-0163.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-0163","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-0163"},"summary":{"title":"CVE-2007-0163","description":"SecureKit Steganography 1.7.1 and 1.8 embeds password information in the carrier file, which allows remote attackers to bypass authentication requirements and decrypt embedded steganography by replacing the last 20 bytes of the JPEG image with alternate password information.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-01-10 00:28:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.8","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:N/A:N","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/23639","name":"http://secunia.com/advisories/23639","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"SecureKit Steganography Carrier File Password Bypass Security Issue - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/31244","name":"http://osvdb.org/31244","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/456519/100/0/threaded","name":"http://www.securityfocus.com/archive/1/456519/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://homepage.mac.com/adonismac/Advisory/steg/steganography.html","name":"http://homepage.mac.com/adonismac/Advisory/steg/steganography.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"","mime":"text/html","httpstatus":"503","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31378","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31378","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/456283/100/0/threaded","name":"http://www.securityfocus.com/archive/1/456283/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-0163","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-0163","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"163","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"securekit","cpe5":"securekit_steganography","cpe6":"1.7.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"163","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"securekit","cpe5":"securekit_steganography","cpe6":"1.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T12:12:17.582Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20070106 Cracking Steganography Application in less than ONE minute","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/456283/100/0/threaded"},{"name":"20070107 A Major design Bug in Steganography 1.7.x, 1.8 (latest) (Updated Version)","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/456519/100/0/threaded"},{"name":"31244","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/31244"},{"name":"steganography-password-security-bypass(31378)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31378"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://homepage.mac.com/adonismac/Advisory/steg/steganography.html"},{"name":"23639","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23639"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-01-06T00:00:00.000Z","descriptions":[{"lang":"en","value":"SecureKit Steganography 1.7.1 and 1.8 embeds password information in the carrier file, which allows remote attackers to bypass authentication requirements and decrypt embedded steganography by replacing the last 20 bytes of the JPEG image with alternate password information."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20070106 Cracking Steganography Application in less than ONE minute","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/456283/100/0/threaded"},{"name":"20070107 A Major design Bug in Steganography 1.7.x, 1.8 (latest) (Updated Version)","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/456519/100/0/threaded"},{"name":"31244","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/31244"},{"name":"steganography-password-security-bypass(31378)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31378"},{"tags":["x_refsource_MISC"],"url":"http://homepage.mac.com/adonismac/Advisory/steg/steganography.html"},{"name":"23639","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23639"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-0163","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"SecureKit Steganography 1.7.1 and 1.8 embeds password information in the carrier file, which allows remote attackers to bypass authentication requirements and decrypt embedded steganography by replacing the last 20 bytes of the JPEG image with alternate password information."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20070106 Cracking Steganography Application in less than ONE minute","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/456283/100/0/threaded"},{"name":"20070107 A Major design Bug in Steganography 1.7.x, 1.8 (latest) (Updated Version)","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/456519/100/0/threaded"},{"name":"31244","refsource":"OSVDB","url":"http://osvdb.org/31244"},{"name":"steganography-password-security-bypass(31378)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31378"},{"name":"http://homepage.mac.com/adonismac/Advisory/steg/steganography.html","refsource":"MISC","url":"http://homepage.mac.com/adonismac/Advisory/steg/steganography.html"},{"name":"23639","refsource":"SECUNIA","url":"http://secunia.com/advisories/23639"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-0163","datePublished":"2007-01-10T00:00:00.000Z","dateReserved":"2007-01-09T00:00:00.000Z","dateUpdated":"2024-08-07T12:12:17.582Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-01-10 00:28:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:N/A:N","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:securekit:securekit_steganography:1.7.1:*:*:*:*:*:*:*","matchCriteriaId":"BAFE088F-1AF2-42CB-B487-F213FD6E5DD1"},{"vulnerable":true,"criteria":"cpe:2.3:a:securekit:securekit_steganography:1.8:*:*:*:*:*:*:*","matchCriteriaId":"B1A8A727-600C-4B45-8C53-88D560E7E345"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"163","Ordinal":"1","Title":"CVE-2007-0163","CVE":"CVE-2007-0163","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"163","Ordinal":"1","NoteData":"SecureKit Steganography 1.7.1 and 1.8 embeds password information in the carrier file, which allows remote attackers to bypass authentication requirements and decrypt embedded steganography by replacing the last 20 bytes of the JPEG image with alternate password information.","Type":"Description","Title":"CVE-2007-0163"},{"CveYear":"2007","CveId":"163","Ordinal":"2","NoteData":"2007-01-09","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"163","Ordinal":"3","NoteData":"2018-10-16","Type":"Other","Title":"Modified"}]}}}