Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Autonomy

First CVE: Dec 31, 2005Active for: 21 yearsTotal CVEs: 25
56.0
VTI Score
TOP TARGET

Autonomy's vulnerability portfolio centers on a specialized set of document-analysis and content-extraction tools, particularly the KeyView SDK family and related filtering and viewing products, which serve integration and enterprise-search use cases. Though the vendor commands a niche market, its products sit deep in document-processing pipelines where they handle untrusted input from a broad range of file formats, creating a sustained exposure surface. The recurring weakness classes—buffer-boundary violations, path-traversal conditions, and link-following flaws—reflect the parsing and file-access demands inherent to format-agnostic document handling. Defenders should prioritize inventory of systems embedding KeyView SDKs and assess the risk posed by untrusted document ingestion, as these products often operate with elevated privilege in back-end workflows; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
25
Total CVEs
More Total CVEs than 97% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
9.2
Avg CVSS Score
Higher Avg CVSS Score than 88% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Autonomy over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2005
20 years ago
Most Recent CVE
Jul 18, 2013
4,754 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2009-0347MEDIUM
Open redirect vulnerability in cs.html in the Autonomy (formerly Verity) Ultraseek search engine allows remote attackers to redirect users to arbitrary web sites and conduct phishi
Jan 29, 20095.836NOYES
CVE-2007-5909HIGH
Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, IBM Lotus Notes befor
Nov 10, 20079.335NONO
CVE-2011-1512HIGH
Heap-based buffer overflow in xlssr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a malformed BIFF rec
May 31, 20119.330NONO
CVE-2011-1218HIGH
Buffer overflow in kvarcve.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted .zip attachment, ak
May 31, 20119.328NONO
CVE-2007-5910HIGH
Stack-based buffer overflow in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, wp6sr.dll in IBM Lotus Notes 8.
Nov 10, 20079.328NONO
CVE-2012-6349HIGH
Buffer overflow in the .mdb parser in Autonomy KeyView IDOL, as used in IBM Notes 8.5.x before 8.5.3 FP4, allows remote attackers to execute arbitrary code via a crafted file, aka
Jul 18, 20139.327NONO
CVE-2010-0134HIGH
Integer signedness error in rtfsr.dll in Autonomy KeyView 10.4 and 10.9, as used in multiple IBM, Symantec, and other products, allows remote attackers to execute arbitrary code vi
Aug 17, 20109.327NONO
CVE-2010-0133HIGH
Multiple stack-based buffer overflows in the SpreadSheet Lotus 123 reader (wkssr.dll) in Autonomy KeyView 10.4 and 10.9, as used in multiple IBM, Symantec, and other products, allo
Aug 17, 20109.326NONO
CVE-2010-0126HIGH
Heap-based buffer overflow in an unspecified library in Autonomy KeyView 10.4 and 10.9, as used in multiple IBM, Symantec, and other products, allows remote attackers to execute ar
Aug 17, 20109.326NONO
CVE-2009-3037HIGH
Buffer overflow in xlssr.dll in the Autonomy KeyView XLS viewer (aka File Viewer for Excel), as used in IBM Lotus Notes 5.x through 8.5.x, Symantec Mail Security, Symantec BrightMa
Sep 1, 20099.326NONO
View all 25 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products25 CVEs
96%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown25 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown25 (100.0%)
User Interaction
None0 (0.0%)
Unknown25 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown25 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (25 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
4.0% of CVEs· 95th percentile
ExploitDB
1 CVE
4.0% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Autonomy.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Autonomy — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Autonomy's Products

View all 2 CNAs →

Top CWEs