AI description
Automated description summarized from trusted sources.
CVE-2025-23339 refers to an Improper Control of Filename vulnerability, specifically a PHP Remote File Inclusion vulnerability, found in the Devnex Addons For Elementor. This vulnerability affects Devnex Addons For Elementor versions up to 1.0.9. An attacker could exploit this vulnerability to achieve PHP Local File Inclusion. This is possible because of the improper control of filenames for include/require statements in PHP programs.
- Description
- NVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump where an attacker may cause a stack-based buffer overflow by getting the user to run cuobjdump on a malicious ELF file. A successful exploit of this vulnerability may lead to arbitrary code execution at the privilege level of the user running cuobjdump.
- Source
- psirt@nvidia.com
- NVD status
- Analyzed
- Products
- cuda_toolkit
CVSS 3.1
- Type
- Primary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
- psirt@nvidia.com
- CWE-121
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nvidia:cuda_toolkit:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "970ED8B6-06F1-46FF-B2A7-F55E719FB1CA",
"versionEndExcluding": "13.0.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"
},
{
"criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
]