CVE-2025-23339

Published Sep 24, 2025

Last updated 3 months ago

CVSS low 3.3
NVIDIA CUDA Toolkit

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-23339 refers to an Improper Control of Filename vulnerability, specifically a PHP Remote File Inclusion vulnerability, found in the Devnex Addons For Elementor. This vulnerability affects Devnex Addons For Elementor versions up to 1.0.9. An attacker could exploit this vulnerability to achieve PHP Local File Inclusion. This is possible because of the improper control of filenames for include/require statements in PHP programs.

Description
NVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump where an attacker may cause a stack-based buffer overflow by getting the user to run cuobjdump on a malicious ELF file. A successful exploit of this vulnerability may lead to arbitrary code execution at the privilege level of the user running cuobjdump.
Source
psirt@nvidia.com
NVD status
Analyzed
Products
cuda_toolkit

Risk scores

CVSS 3.1

Type
Primary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

psirt@nvidia.com
CWE-121

Social media

Hype score
Not currently trending

Configurations