Vulnerabilities > Groove

DATE CVE VULNERABILITY TITLE RISK
2007-12-27 CVE-2007-6530 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Buffer overflow in the XUpload.ocx ActiveX control in Persits Software XUpload 2.1.0.1, and probably other versions before 3.0, as used by HP Mercury LoadRunner and Groove Virtual Office, allows remote attackers to execute arbitrary code via a long argument to the AddFolder function.
network
groove hp persits CWE-119
critical
9.3
2005-05-20 CVE-2005-1678 Remote Security vulnerability in Groove Workspace and Virtual Office
Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 does not properly display file extensions on attached or embedded files in a compound document, which may allow remote attackers to trick users into executing malicious code.
network
high complexity
groove
2.6
2005-05-20 CVE-2005-1677 Security Bypass vulnerability in Groove Workspace and Virtual Office
Unknown vulnerability in Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 allows remote attackers to bypass restrictions on COM objects.
network
low complexity
groove
7.5
2005-05-20 CVE-2005-1676 Unspecified vulnerability in Groove Workspace and Virtual Office
Multiple cross-site scripting (XSS) vulnerabilities in Groove Mobile Workspace in Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 allow remote attackers to inject arbitrary web script or HTML via the (1) picture columns embedded within SharePoint lists or (2) drop-down menus in a SharePoint list.
network
groove
6.8
2005-05-20 CVE-2005-1675 Information Disclosure vulnerability in Groove Workspace and Virtual Office
Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 installs the client installation directories with insecure EVERYBODY permissions, which allows local users to gain sensitive information.
local
low complexity
groove
4.6