Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 does not properly display file extensions on attached or embedded files in a compound document, which may allow remote attackers to trick users into executing malicious code.
2005-05-20T04:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 2.6 (LOW)
AV:N/AC:H/Au:N/C:N/I:P/A:N
4.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | groove | groove_workspace | ≤ 2.5n_build_1871 | Yes |
Application | groove | virtual_office | ≤ 3.1_build_2338 | Yes |
Application | groove | virtual_office | ≤ 3.1a_build_2364 | Yes |