CVE-2019-25551

Sandboxie 5.30 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Program Alerts configuration field. Attackers can paste a buffer of 5000 characters into the 'Select or enter a program' field during program alert configuration to trigger an application crash.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sandboxie-plus:sandboxie:5.30:*:*:*:classic:*:*:*

History

17 Jun 2026, 02:32

Type Values Removed Values Added
Summary
  • (es) Sandboxie 5.30 contiene una vulnerabilidad de denegación de servicio que permite a atacantes locales bloquear la aplicación al introducir una cadena excesivamente larga en el campo de configuración de Alertas de programa. Los atacantes pueden pegar un búfer de 5000 caracteres en el campo 'Seleccionar o introducir un programa' durante la configuración de la alerta de programa para provocar un bloqueo de la aplicación.

23 Mar 2026, 17:06

Type Values Removed Values Added
CPE cpe:2.3:a:sandboxie-plus:sandboxie:5.30:*:*:*:classic:*:*:*
References () https://www.exploit-db.com/exploits/46860 - () https://www.exploit-db.com/exploits/46860 - Exploit, VDB Entry
References () https://www.sandboxie.com - () https://www.sandboxie.com - Product
References () https://www.vulncheck.com/advisories/sandboxie-denial-of-service-via-program-alerts-buffer-overflow - () https://www.vulncheck.com/advisories/sandboxie-denial-of-service-via-program-alerts-buffer-overflow - Third Party Advisory
First Time Sandboxie-plus
Sandboxie-plus sandboxie
CWE CWE-1284

21 Mar 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-21 13:16

Updated : 2026-06-17 02:32


NVD link : CVE-2019-25551

Mitre link : CVE-2019-25551

CVE.ORG link : CVE-2019-25551


JSON object : View

Products Affected

sandboxie-plus

  • sandboxie
CWE
CWE-1282

Assumed-Immutable Data is Stored in Writable Memory

CWE-1284

Improper Validation of Specified Quantity in Input