CVE-2007-6020
Multiple stack-based buffer overflows in foliosr.dll in the Folio Flat File speed reader in Autonomy (formerly Verity) KeyView 10.3.0.0, as used by IBM Lotus Notes, Symantec Mail Security, and activePDF DocConverter, allow remote attackers to execute arbitrary code via a long attribute value in a (1) DI, (2) FD, (3) FT, (4) JD, (5) JL, (6) LE, (7) OB, (8) OD, (9) OL, (10) PN, (11) PS, (12) PW, (13) RD, (14) QL, or (15) TS tag in a .fff file.
Published:Apr 10, 2008
Last Modified:Apr 23, 2026
EPS:Apr 10, 2008
EPSS Score:0.34744
CVSS Score:9.3
Affected Products
Vendor
Product
Action
Vendor
Activepdf
Product
Docconverter
Activepdf
Docconverter
Vendor
Autonomy
Product
Keyview
Autonomy
Keyview
Vendor
Ibm
Product
Lotus Notes
Ibm
Lotus Notes
Vendor
Symantec
Product
Mail Security
Symantec
Mail Security
Vendor
Symantec
Product
Mail Security Appliance
Symantec
Mail Security Appliance
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
