CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “imaginationtech”

17 vulnerabilities found for “imaginationtech”

CVE-2026-21736
MEDIUM4.4

Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to read-only wrapped user-mode memory. This is caused by improper handling of the memory protections for the user-mode wrapped memory resource.

imaginationtech / ddk+1
Local
Published Mar 9, 2026
CVE-2025-13952
CRITICAL9.8

A web page that contains unusual GPU shader code is loaded from the Internet into the GPU compiler process triggers a write use-after-free crash in the GPU shader compiler library. On certain platforms, when the compiler process has system privileges this could enable further exploits on the device. The shader code contained in the web page executes a path in the compiler that held onto an out of date pointer, pointing to a freed memory object.

imaginationtech / ddk
Network
Published Jan 24, 2026
CVE-2025-25176
CRITICAL9.1

Intermediate register values of secure workloads can be exfiltrated in workloads scheduled from applications running in the non-secure environment of a platform.

imaginationtech / ddk
Network
Published Jan 13, 2026
CVE-2025-58409
LOW3.5

Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in use by the kernel and drivers running on the platform altering their behaviour. This attack can lead the GPU to perform write operations on restricted internal GPU buffers that can lead to a second order affect of corrupted arbitrary physical memory.

imaginationtech / ddk
Physical
Published Jan 13, 2026
CVE-2025-10865
HIGH7.8

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of reference counting to cause a potential use after free. Improper reference counting on an internal resource caused scenario where potential for use after free was present.

imaginationtech / ddk
Local
Published Jan 13, 2026
CVE-2025-58411
HIGH8.8

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of resources reference counting creating a potential use after free scenario. Improper resource management and reference counting on an internal resource caused scenario where potential write use after free was present.

imaginationtech / ddk
Local
Published Jan 13, 2026
CVE-2025-58408
MEDIUM5.9

Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger reads of stale data that can lead to kernel exceptions and write use-after-free. The Use After Free common weakness enumeration was chosen as the stale data can include handles to resources in which the reference counts can become unbalanced. This can lead to the premature destruction of a resource while in use.

imaginationtech / ddk
Local
Published Dec 1, 2025
CVE-2025-58407
HIGH7.4

Kernel or driver software installed on a Guest VM may post improper commands to the GPU Firmware to exploit a TOCTOU race condition and trigger a read and/or write of data outside the allotted memory escaping the virtual machine.

imaginationtech / ddk
Network
Published Nov 17, 2025
CVE-2025-58410
HIGH7.5

Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permissions to memory buffers exported as read-only. This is caused by improper handling of the memory protections for the buffer resource.

imaginationtech / ddk+8
Network
Published Nov 17, 2025
CVE-2025-46711
MEDIUM5.5

Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger NULL pointer dereference kernel exceptions.

imaginationtech / ddk
Local
Published Sep 22, 2025
CVE-2025-46709
HIGH7.5

Possible memory leak or kernel exceptions caused by reading kernel heap data after free or NULL pointer dereference kernel exception.

imaginationtech / ddk
Network
Published Aug 9, 2025
CVE-2025-46707
MEDIUM5.2

Software installed and running inside a Guest VM may override Firmware's state and gain access to the GPU.

imaginationtech / ddk+3
Local
Published Jun 27, 2025
CVE-2025-46708
MEDIUM4.3

Software installed and running inside a Guest VM may conduct improper GPU system calls to prevent other Guests from running work on the GPU.

imaginationtech / ddk+3
Physical
Published Jun 27, 2025
CVE-2025-46710
MEDIUM5.7

Possible kernel exceptions caused by reading and writing kernel heap data after free.

imaginationtech / ddk+3
Physical
Published Jun 16, 2025
CVE-2025-25179
HIGH7.8

Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages.

imaginationtech / ddk
Local
Published Jun 2, 2025
CVE-2025-0467
HIGH8.2

Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.

imaginationtech / ddk
Local
Published Apr 18, 2025
CVE-2023-4969
MEDIUM6.5

A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU memory region called _local memory_ on various architectures.

khronos / opencl+139
Local
Published Jan 16, 2024