CVE-2019-25551
Sandboxie 5.30 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Program Alerts configuration field. Attackers can paste a buffer of 5000 characters into the 'Select or enter a program' field during program alert configuration to trigger an application crash.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.17%
- CWE
- CWE-1282
- Published
- 2026-03-21
- Last modified
- 2026-03-23
Affected products
- Sandboxie Sandboxie
Weakness type
Related vulnerabilities
- CVE-2018-25229 — BulletProof FTP Server 2019.0.0.50 Denial of Service via SMTP
- CVE-2019-25590 — Axessh 4.2 Denial of Service via Log File Name
- CVE-2019-25588 — BulletProof FTP Server 2019.0.0.50 Denial of Service via DNS Address
- CVE-2019-25587 — BulletProof FTP Server 2019.0.0.50 Storage-Path Denial of Service
- CVE-2019-25583 — RarmaRadio 2.72.3 Username Field Denial of Service
- CVE-2019-25358 — FileOptimizer 14.00.2524 - Denial of Service
- CVE-2022-2483