CVE-2021-47831
- EPSS 0.01%
- Veröffentlicht 16.01.2026 19:16:08
- Zuletzt bearbeitet 26.01.2026 15:05:57
Sandboxie 5.49.7 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the container folder input field. Attackers can paste a large buffer of repeated characters into the Sandbox container folder se...
- EPSS 0.11%
- Veröffentlicht 11.12.2025 21:15:30
- Zuletzt bearbeitet 22.12.2025 18:44:17
Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.16.6 and below, the SYSTEM-level service SbieSvc.exe exposes SbieIniServer::RC4Crypt to sandboxed processes. The handler adds a fi...
CVE-2025-54422
- EPSS 0.01%
- Veröffentlicht 29.07.2025 12:47:50
- Zuletzt bearbeitet 04.08.2025 17:30:08
Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.16.1 and below, a critical security vulnerability exists in password handling mechanisms. During encrypted sandbox creation, user ...
CVE-2025-46716
- EPSS 0.03%
- Veröffentlicht 22.05.2025 16:50:18
- Zuletzt bearbeitet 04.08.2025 17:26:34
Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in version 1.3.0 and prior to version 1.15.12, Api_SetSecureParam fails to sanitize incoming pointers, and implicitly trusts that the p...
CVE-2025-46715
- EPSS 0.03%
- Veröffentlicht 22.05.2025 16:46:16
- Zuletzt bearbeitet 04.08.2025 17:25:44
Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in version 1.3.0 and prior to version 1.15.12, Api_GetSecureParam fails to sanitize incoming pointers, and implicitly trusts that the p...
CVE-2025-46714
- EPSS 0.03%
- Veröffentlicht 22.05.2025 12:27:57
- Zuletzt bearbeitet 04.08.2025 17:24:44
Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in version 1.3.0 and prior to 1.15.12, API_GET_SECURE_PARAM has an arithmetic overflow leading to a small memory allocation and then a ...
CVE-2025-46713
- EPSS 0.03%
- Veröffentlicht 22.05.2025 12:23:16
- Zuletzt bearbeitet 04.08.2025 17:23:32
Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in version 0.0.1 and prior to 1.15.12, API_SET_SECURE_PARAM may have an arithmetic overflow deep in the memory allocation subsystem tha...
CVE-2024-49360
- EPSS 0.14%
- Veröffentlicht 29.11.2024 18:15:09
- Zuletzt bearbeitet 04.08.2025 17:25:26
Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. An authenticated user (**UserA**) with no privileges is authorized to read all files created in sandbox belonging to other users in the sandbox ...
- EPSS 0.8%
- Veröffentlicht 29.10.2018 12:29:09
- Zuletzt bearbeitet 04.08.2025 20:00:30
Sandboxie 5.26 allows a Sandbox Escape via an "import os" statement, followed by os.system("cmd") or os.system("powershell"), within a .py file. NOTE: the vendor disputes this issue because the observed behavior is consistent with the product's inten...