← Vulnerability feed

Vulnerability record · CVE-2009-3032 · published 5 March 2010

CVE-2009-3032: Ibm lotus notes vulnerability

Ibm · Lotus Notes

Integer overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used in IBM Lotus Notes 8.5, Symantec Mail Security for Microsoft Exchange 5.0.10 through 5.0.13, and other products, allows context-dependent attackers to execute arbitrary code via a crafted OLE document that triggers a heap-based buffer overflow.

10.0 CVSS 2.0 High EPSS 3.7% · top 10.6% CWE-189 · CWE-189
10.0CVSS 2.0 base score
3.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
8References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Integer overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used in IBM Lotus Notes 8.5, Symantec Mail Security for Microsoft Exchange 5.0.10 through 5.0.13, and other products, allows context-dependent attackers to execute arbitrary code via a crafted OLE document that triggers a heap-based buffer overflow.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-3032 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-1608Ibm lotus notes memory buffer overflow vulnerabilityStack-based buffer overflow in IBM Lotus Notes 8.5 and 8.5fp1, and possibly other versions, allows remote attackers to execute arbitrary code via unk…EPSS 5.8%10.0CVE-2006-0119Ibm lotus domino vulnerabilityMultiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 have unknown impact and attack vectors, due to "potential secu…EPSS 3.8%10.0CVE-2004-2281Ibm lotus notes vulnerabilityMultiple unknown vulnerabilities in IBM Lotus Notes 6.5.x before 6.5.4 and 6.0.x before 6.0.5 have unknown impact and attack vectors, related to Java…EPSS 2.2%10.0CVE-2004-0480Ibm lotus notes argument injection vulnerabilityArgument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to execute arbitrary code via a notes: URI that uses a UNC …EPSS 8.6%9.3CVE-2012-6349Autonomy keyview idol memory buffer overflow vulnerabilityBuffer overflow in the .mdb parser in Autonomy KeyView IDOL, as used in IBM Notes 8.5.x before 8.5.3 FP4, allows remote attackers to execute arbitrar…EPSS 3.2%9.3CVE-2012-4821Ibm java vulnerabilityMultiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 …EPSS 6.9%9.3CVE-2012-4822Ibm java vulnerabilityMultiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 …EPSS 6.9%9.3CVE-2012-4823Ibm java vulnerabilityUnspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and ea…EPSS 6.9%

Source: NIST National Vulnerability Database (record CVE-2009-3032), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.