CVE-2019-25551

Sandboxie 5.30 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Program Alerts configuration field. Attackers can paste a buffer of 5000 characters into the 'Select or enter a program' field during program alert configuration to trigger an application crash.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sandboxie-plus:sandboxie:5.30:*:*:*:classic:*:*:*

History

23 Mar 2026, 17:06

Type Values Removed Values Added
CPE cpe:2.3:a:sandboxie-plus:sandboxie:5.30:*:*:*:classic:*:*:*
References () https://www.exploit-db.com/exploits/46860 - () https://www.exploit-db.com/exploits/46860 - Exploit, VDB Entry
References () https://www.sandboxie.com - () https://www.sandboxie.com - Product
References () https://www.vulncheck.com/advisories/sandboxie-denial-of-service-via-program-alerts-buffer-overflow - () https://www.vulncheck.com/advisories/sandboxie-denial-of-service-via-program-alerts-buffer-overflow - Third Party Advisory
First Time Sandboxie-plus
Sandboxie-plus sandboxie
CWE CWE-1284

21 Mar 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-21 13:16

Updated : 2026-03-23 17:06


NVD link : CVE-2019-25551

Mitre link : CVE-2019-25551

CVE.ORG link : CVE-2019-25551


JSON object : View

Products Affected

sandboxie-plus

  • sandboxie
CWE
CWE-1282

Assumed-Immutable Data is Stored in Writable Memory

CWE-1284

Improper Validation of Specified Quantity in Input