Autonomy's vulnerability portfolio centers on a specialized set of document-analysis and content-extraction tools, particularly the KeyView SDK family and related filtering and viewing products, which serve integration and enterprise-search use cases. Though the vendor commands a niche market, its products sit deep in document-processing pipelines where they handle untrusted input from a broad range of file formats, creating a sustained exposure surface. The recurring weakness classes—buffer-boundary violations, path-traversal conditions, and link-following flaws—reflect the parsing and file-access demands inherent to format-agnostic document handling. Defenders should prioritize inventory of systems embedding KeyView SDKs and assess the risk posed by untrusted document ingestion, as these products often operate with elevated privilege in back-end workflows; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Autonomy over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-0347MEDIUM Open redirect vulnerability in cs.html in the Autonomy (formerly Verity) Ultraseek search engine allows remote attackers to redirect users to arbitrary web sites and conduct phishi | Jan 29, 2009 | 5.8 | 36 | NO | YES |
CVE-2007-5909HIGH Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, IBM Lotus Notes befor | Nov 10, 2007 | 9.3 | 35 | NO | NO |
CVE-2011-1512HIGH Heap-based buffer overflow in xlssr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a malformed BIFF rec | May 31, 2011 | 9.3 | 30 | NO | NO |
CVE-2011-1218HIGH Buffer overflow in kvarcve.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted .zip attachment, ak | May 31, 2011 | 9.3 | 28 | NO | NO |
CVE-2007-5910HIGH Stack-based buffer overflow in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, wp6sr.dll in IBM Lotus Notes 8. | Nov 10, 2007 | 9.3 | 28 | NO | NO |
CVE-2012-6349HIGH Buffer overflow in the .mdb parser in Autonomy KeyView IDOL, as used in IBM Notes 8.5.x before 8.5.3 FP4, allows remote attackers to execute arbitrary code via a crafted file, aka | Jul 18, 2013 | 9.3 | 27 | NO | NO |
CVE-2010-0134HIGH Integer signedness error in rtfsr.dll in Autonomy KeyView 10.4 and 10.9, as used in multiple IBM, Symantec, and other products, allows remote attackers to execute arbitrary code vi | Aug 17, 2010 | 9.3 | 27 | NO | NO |
CVE-2010-0133HIGH Multiple stack-based buffer overflows in the SpreadSheet Lotus 123 reader (wkssr.dll) in Autonomy KeyView 10.4 and 10.9, as used in multiple IBM, Symantec, and other products, allo | Aug 17, 2010 | 9.3 | 26 | NO | NO |
CVE-2010-0126HIGH Heap-based buffer overflow in an unspecified library in Autonomy KeyView 10.4 and 10.9, as used in multiple IBM, Symantec, and other products, allows remote attackers to execute ar | Aug 17, 2010 | 9.3 | 26 | NO | NO |
CVE-2009-3037HIGH Buffer overflow in xlssr.dll in the Autonomy KeyView XLS viewer (aka File Viewer for Excel), as used in IBM Lotus Notes 5.x through 8.5.x, Symantec Mail Security, Symantec BrightMa | Sep 1, 2009 | 9.3 | 26 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Autonomy.
Media articles that mention a CVE ID that affects a product developed by Autonomy — matched by CVE ID, not by vendor name.