← Vulnerability feed

Vulnerability record · CVE-2005-2619 · published 31 December 2005

CVE-2005-2619: Autonomy keyview export sdk path traversal vulnerability

Autonomy · Keyview Export Sdk

Directory traversal vulnerability in kvarcve.dll in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allows remote attackers to delete arbitrary files via a (1) ZIP, (2) UUE or (3) TAR archive that contains a .. (dot dot) in the filename, which is not properly handled when generating a preview.

9.3 CVSS 2.0 High EPSS 3.3% · top 12.0% CWE-22 · Path traversal
9.3CVSS 2.0 base score
3.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
22References
16 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in kvarcve.dll in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allows remote attackers to delete arbitrary files via a (1) ZIP, (2) UUE or (3) TAR archive that contains a .. (dot dot) in the filename, which is not properly handled when generating a preview.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-2619 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-1608Ibm lotus notes memory buffer overflow vulnerabilityStack-based buffer overflow in IBM Lotus Notes 8.5 and 8.5fp1, and possibly other versions, allows remote attackers to execute arbitrary code via unk…EPSS 5.8%10.0CVE-2009-3032Ibm lotus notes vulnerabilityInteger overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used in IBM Lotus Notes 8.5, Symantec Mail Security f…EPSS 3.7%10.0CVE-2006-0119Ibm lotus domino vulnerabilityMultiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 have unknown impact and attack vectors, due to "potential secu…EPSS 3.8%10.0CVE-2004-2281Ibm lotus notes vulnerabilityMultiple unknown vulnerabilities in IBM Lotus Notes 6.5.x before 6.5.4 and 6.0.x before 6.0.5 have unknown impact and attack vectors, related to Java…EPSS 2.2%10.0CVE-2004-0480Ibm lotus notes argument injection vulnerabilityArgument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to execute arbitrary code via a notes: URI that uses a UNC …EPSS 8.6%9.3CVE-2012-6349Autonomy keyview idol memory buffer overflow vulnerabilityBuffer overflow in the .mdb parser in Autonomy KeyView IDOL, as used in IBM Notes 8.5.x before 8.5.3 FP4, allows remote attackers to execute arbitrar…EPSS 3.2%9.3CVE-2012-4822Ibm java vulnerabilityMultiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 …EPSS 6.9%9.3CVE-2012-4823Ibm java vulnerabilityUnspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and ea…EPSS 6.9%

Source: NIST National Vulnerability Database (record CVE-2005-2619), CISA KEV, FIRST EPSS (scores of 2026-10-01). This page is refreshed as NVD updates the record.