Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/imaginationtechnologies/graphics-ddk

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

A web page that contains unusual GPU shader code is loaded from the Internet into the GPU compiler process triggers a write use-after-free crash in the GPU shader compiler library. On certain platforms, when the compiler process has system privileges this could enable further exploits on the device. The shader code contained in the web page executes a path in the compiler that held onto an out of date pointer, pointing to a freed memory object.

Join the discussion

CVE-2025-10865 is a high-severity use-after-free vulnerability in Imagination Technologies' Graphics DDK affecting versions 1.15 RTM, 1.17 RTM, 1.18 RTM, and 23.2 RTM. The flaw arises from improper reference counting of internal GPU resources when software running as a non-privileged user issues certain GPU system calls, leading to potential use-after-free conditions. Exploitation could allow an attacker to execute arbitrary code with limited privileges, impacting confidentiality, integrity, and availability of affected systems. No known exploits are currently in the wild. The vulnerability requires local access with low privileges but no user interaction. European organizations using affected Graphics DDK versions in embedded or graphics-intensive devices should prioritize patching once available.

Join the discussion

CVE-2025-58409 is a vulnerability in Imagination Technologies Graphics DDK that allows non-privileged software to misuse GPU system calls to write to arbitrary physical memory. This improper restriction of operations within GPU memory buffers (CWE-119) can corrupt kernel and driver memory pages, potentially altering system behavior. The vulnerability affects multiple versions of the Graphics DDK and does not require user interaction or privileges to exploit. Although the CVSS score is low (3.5), the ability to write to arbitrary physical memory poses risks to system integrity. No known exploits are currently in the wild, and no patches have been released yet. European organizations using affected GPU drivers in embedded or specialized systems may be at risk. Mitigation involves restricting access to GPU interfaces, monitoring GPU driver updates, and applying vendor patches once available. Countries with significant embedded systems manufacturing and technology sectors, such as Germany, France, and the UK, are more likely to be impacted.

Join the discussion

Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permissions to memory buffers exported as read-only. This is caused by improper handling of the memory protections for the buffer resource.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Package: pkg:github/imaginationtechnologies/graphics-ddk
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses