Back

CVE-2005-2619

Directory traversal vulnerability in kvarcve.dll in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allows remote attackers to delete arbitrary files via a (1) ZIP, (2) UUE or (3) TAR archive that contains a .. (dot dot) in the filename, which is not properly handled when generating a preview.

Published: Dec 31, 2005 Modified: Jun 16, 2026
CWE-22

CVSS Metrics

Affected Products (14)

Vendor Product Version
autonomy keyview_export_sdk *
autonomy keyview_filter_sdk *
autonomy keyview_viewer_sdk *
ibm lotus_notes 6.0.1
ibm lotus_notes 6.0.2
ibm lotus_notes 6.0.3
ibm lotus_notes 6.0.4
ibm lotus_notes 6.0.5
ibm lotus_notes 6.5
ibm lotus_notes 6.5.1
ibm lotus_notes 6.5.2
ibm lotus_notes 6.5.3
ibm lotus_notes 6.5.4
ibm lotus_notes 7.0

GitHub Security Advisory GHSA-95h6-22hh-49ff

Directory traversal vulnerability in kvarcve.dll in Autonomy (formerly Verity) KeyView SDK before...

Risk Scores

CVSS Score 9.3 / 10
EPSS Score 3.28%

Top 13% most likely to be exploited

Threat Score 38.2 / 100

Data Sources

NVD EPSS GitHub