CVE-2025-46714

Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in version 1.3.0 and prior to 1.15.12, API_GET_SECURE_PARAM has an arithmetic overflow leading to a small memory allocation and then a extremely large copy into the small allocation. Version 1.15.12 fixes the issue.
Configurations

No configuration.

History

23 May 2025, 15:55

Type Values Removed Values Added
Summary
  • (es) Sandboxie es un software de aislamiento basado en la sandbox para sistemas operativos Windows NT de 32 y 64 bits. A partir de la versión 1.3.0 y anteriores a la 1.15.12, API_GET_SECURE_PARAM presenta un desbordamiento aritmético que provoca una pequeña asignación de memoria y, posteriormente, una copia extremadamente grande en dicha asignación. La versión 1.15.12 corrige este problema.

22 May 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-22 13:15

Updated : 2025-05-23 15:55


NVD link : CVE-2025-46714

Mitre link : CVE-2025-46714

CVE.ORG link : CVE-2025-46714


JSON object : View

Products Affected

No product.

CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')