-
1
-
-
35448955692
-
Valgrind: A framework for heavy weight dynamic binary instrumentation
-
San Diego, California, USA, June
-
N.Nethercote and J. Seward. Valgrind: A framework for heavy weight dynamic binary instrumentation. In Proceedings of PLDI 2007, San Diego, California, USA, June 2007.
-
(2007)
Proceedings of PLDI
-
-
Nethercote, N.1
Seward, J.2
-
2
-
-
70349886980
-
-
D. A. Molnar and D. Wagner. Catchconv: Symbolic execution and run-time type inference for integer conversion errors. Technical Report UCB/EECS-2007-23, EECS Department, University of California, Berkeley, February 2007.
-
D. A. Molnar and D. Wagner. Catchconv: Symbolic execution and run-time type inference for integer conversion errors. Technical Report UCB/EECS-2007-23, EECS Department, University of California, Berkeley, February 2007.
-
-
-
-
4
-
-
70349863791
-
-
May,2007, Online, Available
-
CVE: Vulnerability Type Distributions. May,2007. [Online]. Available: http://cve.mitre.org/docs/vuln-trends/vuln-trends.pdf.
-
Vulnerability Type Distributions
-
-
-
5
-
-
70349863790
-
-
VLC Media Player Integer signedness error vulnerability, CVE, 2008. [Online]. Available: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name= CVE-2008-3794.
-
"VLC Media Player Integer signedness error vulnerability," CVE, 2008. [Online]. Available: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name= CVE-2008-3794.
-
-
-
-
6
-
-
70349851404
-
-
VLC Media Player Integer overflow vulnerability, CVE, 2008.[Online]. Available: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE- 2008-3732.
-
"VLC Media Player Integer overflow vulnerability," CVE, 2008.[Online]. Available: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE- 2008-3732.
-
-
-
-
7
-
-
70349856590
-
-
Linux Kernel Integer underflow vulnerability, CVE, 2007. [Online]. Available: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007- 4997.
-
"Linux Kernel Integer underflow vulnerability," CVE, 2007. [Online]. Available: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007- 4997.
-
-
-
-
8
-
-
70349851407
-
-
SSH CRC-32 compensation attack detector vulnerability, CVE, Feb 2001. [Online]. Available: http://www.cve.mitre.org/cgi-bin/cvename.cgi? name=CVE-2001-0144.
-
"SSH CRC-32 compensation attack detector vulnerability," CVE, Feb 2001. [Online]. Available: http://www.cve.mitre.org/cgi-bin/cvename.cgi? name=CVE-2001-0144.
-
-
-
-
9
-
-
70349863789
-
-
R. Wojtczuk. Uqbtng: a tool capable of automatically finding integer overflows in win32 binaries. In 22nd Chaos Communication Congress, 2005.
-
R. Wojtczuk. Uqbtng: a tool capable of automatically finding integer overflows in win32 binaries. In 22nd Chaos Communication Congress, 2005.
-
-
-
-
11
-
-
70349885896
-
-
Phrack Inc, Dec 2002, Online, Available
-
O. Horovitz. Big loop integer protection. Phrack Inc., Dec 2002. [Online]. Available: http://www.phrack.org/issues.html?issue=60&id= 9#article.
-
Big loop integer protection
-
-
Horovitz, O.1
-
15
-
-
70349877317
-
-
Ada95 Language Reference Manual, ISO/IEC, 1995.
-
Ada95 Language Reference Manual, ISO/IEC, 1995.
-
-
-
-
17
-
-
85084164164
-
Cyclone: A safe dialect of c
-
T. Jim, G. Morrisett, D. Grossman,M. Hicks, J.Cheney, and Y.Wang, Cyclone: A safe dialect of c, in USENIX Annual Technical Conference, 2002.
-
(2002)
USENIX Annual Technical Conference
-
-
Jim, T.1
Morrisett, G.2
Grossman, D.3
Hicks, M.4
Cheney, J.5
Wang, Y.6
-
18
-
-
84870666315
-
-
GNU mailutils imap4d remote integer overflow vulnerability, Sep 2004, Online, Available
-
"GNU mailutils imap4d remote integer overflow vulnerability," SecurityFocus, Sep 2004. [Online]. Available: http://www.securityfocus.com/bid/ 11198/.
-
SecurityFocus
-
-
-
19
-
-
70349867141
-
-
Linux Kernel Integer underflow vulnerability, CVE, 2007. [Online]. Available: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007- 2875.
-
"Linux Kernel Integer underflow vulnerability," CVE, 2007. [Online]. Available: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007- 2875.
-
-
-
-
20
-
-
70349877312
-
-
Gocr ReadPGM NetPBM remote client-side integer overflow vulnerability, CVE, April 2005. [Online].Available: http://cve.mitre.org/ cgi-bin/cvename.cgi?name=CVE-2005-1141.
-
"Gocr ReadPGM NetPBM remote client-side integer overflow vulnerability," CVE, April 2005. [Online].Available: http://cve.mitre.org/ cgi-bin/cvename.cgi?name=CVE-2005-1141.
-
-
-
-
22
-
-
70349886976
-
-
Integer overflow in PHP 5.2.5 and prior, CVE, 2008. [Online]. Available: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1384.
-
"Integer overflow in PHP 5.2.5 and prior," CVE, 2008. [Online]. Available: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1384.
-
-
-
-
23
-
-
70349858718
-
-
Dec, 2006, Online, Available
-
Michael Howard. Integer Overflow and operator::new, Dec, 2006. [Online]. Available: http://blogs.msdn.com/michael-howard/archive/2005/12/06/500629.aspx.
-
Integer Overflow and operator::new
-
-
Howard, M.1
-
24
-
-
85011293817
-
-
David Evans, John Guttag, James Horning, and Yang Meng Tan. LCLint:A tool for using specification to check code. In Proceedings of the ACM SIGSOFT 94 Symposium on the Foundations of Software Engineering, pages 87-96,1994.
-
David Evans, John Guttag, James Horning, and Yang Meng Tan. LCLint:A tool for using specification to check code. In Proceedings of the ACM SIGSOFT 94 Symposium on the Foundations of Software Engineering, pages 87-96,1994.
-
-
-
-
27
-
-
33745798878
-
-
PaX Project
-
PaX Project. The PaX project, 2004. http://pax. grsecurity.net/.
-
(2004)
The PaX project
-
-
-
30
-
-
85084160243
-
Stack-Guard:Automatic adaptive detection and prevention of buffer-overflow attacks
-
San Antonio, Texas,January
-
C. Cowan,C. Pu,D.Maier,J.Walpole et al. Stack-Guard:Automatic adaptive detection and prevention of buffer-overflow attacks. In Proceedings of the 7th USENIX Security Conference, San Antonio, Texas,January,1998.
-
(1998)
Proceedings of the 7th USENIX Security Conference
-
-
Cowan, C.1
Pu, C.2
Maier, D.3
Walpole, J.4
-
31
-
-
85084161775
-
FormatGuard: Automatic protection from printf format string vulnerabilities
-
C.Cowan, M.Barringer, S. Beattie, G.Kroah-Hartman, M.Frantzen, and J.Lokier. FormatGuard: Automatic protection from printf format string vulnerabilities. In Proceedings of the Usenix Security Symposium, 2001.
-
(2001)
Proceedings of the Usenix Security Symposium
-
-
Cowan, C.1
Barringer, M.2
Beattie, S.3
Kroah-Hartman, G.4
Frantzen, M.5
Lokier, J.6
-
34
-
-
85009448253
-
PointGuard: Protecting pointers from buffer overflow vulnerabilities
-
C.Cowan, S.Beatties, J.Johansen, and P.Wagle. PointGuard: Protecting pointers from buffer overflow vulnerabilities. In Proceedings of the Usenix Security Symposium, pages 91-104,2003.
-
(2003)
Proceedings of the Usenix Security Symposium
, pp. 91-104
-
-
Cowan, C.1
Beatties, S.2
Johansen, J.3
Wagle, P.4
-
36
-
-
33845919861
-
-
Z.Lin, B.Mao and L.Xie. LibsafeXP:A Pratical and Transparent Tool for Run-time Buffer Overflow Preventions. In Proc. Of the 7th Annual IEEE Information Assurance Workshop(IAW06).West Point, NY. USA, June, 2006.
-
Z.Lin, B.Mao and L.Xie. LibsafeXP:A Pratical and Transparent Tool for Run-time Buffer Overflow Preventions. In Proc. Of the 7th Annual IEEE Information Assurance Workshop(IAW06).West Point, NY. USA, June, 2006.
-
-
-
-
38
-
-
70349851400
-
-
CVE version: 20061101, CVE. [Online].Available: http://www.cve.mitre.org/ cgi-bin/cvekey.cgi?keyword=integer.
-
CVE version: 20061101, CVE. [Online].Available: http://www.cve.mitre.org/ cgi-bin/cvekey.cgi?keyword=integer.
-
-
-
-
40
-
-
53349100043
-
Convicting exploitable software vulnerabilities: An efficient input provenance based approach
-
Anchorage, Alaska, USA, June
-
Z. Lin, X. Zhang, and D. Xu. Convicting exploitable software vulnerabilities: An efficient input provenance based approach. In Proceedings of the 38th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN'08), Anchorage, Alaska, USA, June 2008.
-
(2008)
Proceedings of the 38th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN'08)
-
-
Lin, Z.1
Zhang, X.2
Xu, D.3
|