google / oss-fuzz-vulns
OSS-Fuzz vulnerabilities for OSV.
☆133Updated this week
Related projects ⓘ
Alternatives and complementary repositories for oss-fuzz-vulns
- Fuzz Introspector -- introspect, extend and optimise fuzzers☆378Updated this week
- CodeQL queries developed by Trail of Bits☆75Updated this week
- ☆28Updated last month
- Post Processor for Facebook Static Analysis Tools.☆133Updated this week
- Collection of community-driven CodeQL query, library and extension packs☆74Updated last week
- CodeQL workshops for GitHub Universe☆91Updated 2 years ago
- Testability Pattern Catalogs for SAST☆29Updated 8 months ago
- Grammar-based HTTP/2 fuzzer with mutation ability☆42Updated 2 years ago
- Run CodeQL queries at scale using Multi-Repository Variant Analysis (MRVA)☆49Updated 7 months ago
- The OpenSSF CVE Benchmark consists of code and metadata for over 200 real life CVEs, as well as tooling to analyze the vulnerable codebas…☆141Updated 8 months ago
- Prepackaged and precompiled github codeql container for rapid analysis, deployment and development.☆109Updated 11 months ago
- GraphFuzz is an experimental framework for building structure-aware, library API fuzzers.☆254Updated 10 months ago
- Vulnerability database and package search for sources such as Linux, OSV, NVD, GitHub and npm. Powered by sqlite, CVE 5.0, purl, and vers…☆98Updated this week
- Grammar-based HTTP/1 fuzzer with mutation ability☆243Updated 3 weeks ago
- ☆58Updated last year
- PASTIS: Collaborative Fuzzing Framework☆157Updated 3 months ago
- CodeQL zero to hero blog post series challenges☆86Updated 3 months ago
- FitM, the Fuzzer in the Middle, can fuzz client and server binaries at the same time using userspace snapshot-fuzzing and network emulati…☆279Updated 2 years ago
- A variant analysis and visualisation tool that scans codebases for similar vulnerabilities☆69Updated 2 years ago
- A taxonomy of attacks on software supply chains in the form of an attack tree, based on and linked to numerous real-world incidents and o…☆71Updated 3 weeks ago
- Artifact for ICSE 2023☆45Updated 2 years ago
- Personal CodeQL queries☆58Updated last week
- JAW: A Graph-based Security Analysis Framework for Client-side JavaScript☆99Updated last week
- AutoSpear☆54Updated 10 months ago
- Mayhem example templates for programming languages and fuzzers that you love!☆27Updated 10 months ago
- A collection of test cases in the Java language. It contains examples for 112 different CWEs.☆52Updated 3 years ago
- Atropos: Effective Fuzzing of Web Applications for Server-Side Vulnerabilities☆53Updated 3 months ago
- FUGIO: Automatic Exploit Generation for PHP Object Injection Vulnerabilities☆90Updated 11 months ago
- Witcher is the first framework for using AFL to fuzz web applications.☆77Updated 11 months ago
- Plume is a code representation benchmarking library with options to extract the AST from Java bytecode and store the result in various gr…☆70Updated last month