Vulnerabilities and Security Patches Detection in OSS: A Survey

R Lin, Y Fu, W Yi, J Yang, J Cao, Z Dong, F ** open-source software (OSS) up to date is one potential solution to prevent known
vulnerabilities. However, it requires frequent and costly testing and may introduce …

Insight: Exploring cross-ecosystem vulnerability impacts

M Xu, Y Wang, SC Cheung, H Yu, Z Zhu - Proceedings of the 37th IEEE …, 2022 - dl.acm.org
Vulnerabilities, referred to as CLV issues, are induced by cross-language invocations of
vulnerable libraries. Such issues greatly increase the attack surface of Python/Java projects …

[PDF][PDF] Syzbridge: Bridging the gap in exploitability assessment of linux kernel bugs in the linux ecosystem

X Zou, Y Hao, Z Zhang, J Pu, W Chen, Z Qian - NDSS, 2024 - par.nsf.gov
Continuous fuzzing has become an integral part of the Linux kernel ecosystem, discovering
thousands of bugs over the past few years. Interestingly, only a tiny fraction of them were …

Understanding the practice of security patch management across multiple branches in oss projects

X Tan, Y Zhang, J Cao, K Sun, M Zhang… - Proceedings of the ACM …, 2022 - dl.acm.org
Since the users of open source software (OSS) projects may not use the latest version all the
time, OSS development teams often support code maintenance for old versions through …

Precise (un) affected version analysis for web vulnerabilities

Y Shi, Y Zhang, T Luo, X Mao, M Yang - Proceedings of the 37th IEEE …, 2022 - dl.acm.org
Web applications are attractive attack targets given their popularity and large number of
vulnerabilities. To mitigate the threat of web vulnerabilities, an important piece of information …