Groove's vulnerability footprint centers on its virtual office and workspace collaboration products, which represent a niche but strategically positioned attack surface within enterprise communication platforms. The observed weaknesses cluster around memory-safety issues and operational boundary enforcement, reflecting the complexity inherent to real-time collaborative software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Groove over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-6530HIGH Buffer overflow in the XUpload.ocx ActiveX control in Persits Software XUpload 2.1.0.1, and probably other versions before 3.0, as used by HP Mercury LoadRunner and Groove Virtual | Dec 27, 2007 | 9.3 | 62 | NO | YES |
CVE-2005-1677HIGH Unknown vulnerability in Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 allows remote attackers to bypass restrict | May 20, 2005 | 7.5 | 20 | NO | NO |
CVE-2005-1676MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Groove Mobile Workspace in Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2 | May 20, 2005 | 6.8 | 19 | NO | NO |
CVE-2005-1675MEDIUM Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 installs the client installation directories with insecure EVERYBOD | May 20, 2005 | 4.6 | 14 | NO | NO |
Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 does not properly display file extensions on attached or embedded f | May 20, 2005 | 2.6 | 12 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Groove.
Media articles that mention a CVE ID that affects a product developed by Groove — matched by CVE ID, not by vendor name.