Search Results - JavaScript engine vulnerability*
-
1
A Review on JavaScript Engine Vulnerability Mining
ISSN: 1742-6588, 1742-6596Published: Bristol IOP Publishing 01.02.2021Published in Journal of physics. Conference series (01.02.2021)“… However, due to the characteristics of JavaScript language and inconsistent browser implementation, the vulnerability of JavaScript execution engine has become a major hidden danger of browser security…”
Get full text
Journal Article -
2
Vulnerable JavaScript functions detection using stacking of convolutional neural networks
ISSN: 2376-5992, 2376-5992Published: United States PeerJ. Ltd 29.02.2024Published in PeerJ. Computer science (29.02.2024)“… These models use vulnerable information and code features to detect related vulnerable code. For identifying different vulnerabilities in JavaScript functions, an approach…”
Get full text
Journal Article -
3
LLM-Guided Mutation Location Selection for Vulnerability-Aware JavaScript Engine Fuzzing
ISSN: 2324-9013Published: IEEE 14.11.2025Published in IEEE ... International Conference on Trust, Security and Privacy in Computing and Communications (Online) (14.11.2025)“…Modern JavaScript engines employ multi-tier JIT compilation for high performance, but these aggressive optimizations often introduce subtle and hard-to-detect security vulnerabilities…”
Get full text
Conference Proceeding -
4
Inherited Vulnerabilities: Javascript Engine V4 secure coding compared to Googles V8
ISSN: 2644-3163Published: IEEE 01.10.2019Published in IEEE Annual Information Technology, Electronics and Mobile Communication Conference (Online) (01.10.2019)“…In 2013, the Qt Project announced a move away from Google's V8 JavaScript engine to their own internal V4 JavaScript engine…”
Get full text
Conference Proceeding -
5
Study of JavaScript Static Analysis Tools for Vulnerability Detection in Node.js Packages
ISSN: 0018-9529, 1558-1721Published: New York IEEE 01.12.2023Published in IEEE transactions on reliability (01.12.2023)“…With the emergence of the Node.js ecosystem, JavaScript has become a widely used programming language for implementing server-side web applications…”
Get full text
Journal Article -
6
PatchFuzz: Patch fuzzing for JavaScript engines
ISSN: 0950-5849Published: Elsevier B.V 01.06.2026Published in Information and software technology (01.06.2026)“… While researchers have made efforts to apply patch fuzzing to testing JavaScript (JS) engines with considerable success, these efforts have been limited to using ordinary test cases or publicly available vulnerability PoCs (Proof of Concepts…”
Get full text
Journal Article -
7
JITBULL: Securing JavaScript Runtime with a Go/No-Go Policy for JIT Engine
ISSN: 2158-3927Published: IEEE 24.06.2024Published in Proceedings - International Conference on Dependable Systems and Networks (24.06.2024)“…Nowadays, most services are delivered through the web and thus heavily rely on JavaScript (JS…”
Get full text
Conference Proceeding -
8
HFF-JIT: A Hybrid Fuzzing Framework for JIT Compiler Vulnerability Detection in JavaScript
ISSN: 2693-9371Published: IEEE 16.07.2025Published in IEEE International Conference on Software Quality, Reliability and Security Companion (QRS-C) (Online) (16.07.2025)“…Just-In-Time(JIT) compilers embedded in JavaScript engines significantly boost runtime performance but also introduce difficult-to-detect vulnerabilities…”
Get full text
Conference Proceeding -
9
iHVI: AN OPEN-SOURCE TOOLKIT FOR CONSTRUCTING INTEGRATED HEAT VULNERABILITY INDEX IN AUSTRALIA
ISSN: 2194-9034, 1682-1750, 2194-9034Published: Gottingen Copernicus GmbH 17.10.2022Published in International archives of the photogrammetry, remote sensing and spatial information sciences. (17.10.2022)“…To tackle the increasing issue of heat risk in Australia and pressure of population growth, this project aimed to establish a first nationwide dynamic and interactive heat vulnerability assessment toolkit…”
Get full text
Journal Article Conference Proceeding -
10
JFuzzer: Detecting Optimization Errors in JavaScript Just-In-Time Compilers
ISSN: 2693-9371Published: IEEE 01.07.2024Published in IEEE International Conference on Software Quality, Reliability and Security Companion (QRS-C) (Online) (01.07.2024)“… This poses challenges for JavaScript engines. Consequently, in response to this situation, modern JavaScript engines are equipped with efficient just-in-time (JIT) compilers…”
Get full text
Conference Proceeding -
11
Wasmati: An efficient static vulnerability scanner for WebAssembly
ISSN: 0167-4048, 1872-6208Published: Amsterdam Elsevier Ltd 01.07.2022Published in Computers & security (01.07.2022)“…WebAssembly is a new binary instruction format that allows targeted compiled code written in high-level languages to be executed with near-native speed by the browser’s JavaScript engine…”
Get full text
Journal Article -
12
Method for Mutation of Complexly Structured Input Data during Fuzzing of JavaScript Engines
ISSN: 2079-8156, 2220-6426Published: 2023Published in Trudy Instituta sistemnogo programmirovaniâ (2023)“…Fuzzing of JavaScript engines is one of the most difficult areas in web-browser testing due to the complexity of input data generating…”
Get full text
Journal Article -
13
Keep Me Updated: An Empirical Study on Embedded JavaScript Engines in Android Apps
ISSN: 2574-3864Published: ACM 15.04.2024Published in Proceedings (IEEE/ACM International Conference on Mining Software Repositories. Online) (15.04.2024)“…Although JavaScript (JS) has been widely used in mobile development, little is known about the security implications of utilizing JS engines shipped as native app libraries…”
Get full text
Conference Proceeding -
14
Linear Matching of JavaScript Regular Expressions
ISSN: 2475-1421, 2475-1421Published: New York, NY, USA ACM 20.06.2024Published in Proceedings of ACM on programming languages (20.06.2024)“… blowups, a frequent source of denial-of-service vulnerabilities in JavaScript applications…”
Get full text
Journal Article -
15
Evaluating seed selection for fuzzing JavaScript engines
ISSN: 1382-3256, 1573-7616Published: New York Springer US 01.11.2023Published in Empirical software engineering : an international journal (01.11.2023)“… However, popular JavaScript engines that have been widely utilized by web browsers to interpret JS code, have become the most common targets for attackers…”
Get full text
Journal Article -
16
Fuzzing JavaScript JIT compilers with a high-quality differential test oracle
ISSN: 0167-4048Published: Elsevier Ltd 01.12.2025Published in Computers & security (01.12.2025)“…Modern JavaScript engines use Just-In-Time (JIT) compilers to convert frequently executed code into machine instructions, boosting performance for web applications and cross-platform systems…”
Get full text
Journal Article -
17
Platform-Independent Dynamic Taint Analysis for JavaScript
ISSN: 0098-5589, 1939-3520Published: New York IEEE 01.12.2020Published in IEEE transactions on software engineering (01.12.2020)“…Previous approaches to dynamic taint analysis for JavaScript are implemented directly in a browser or JavaScript engine, limiting their applicability to a single platform and requiring ongoing…”
Get full text
Journal Article -
18
On DoS Vulnerability of Regular Expressions, with and Without Backreferences
ISSN: 2374-8303Published: IEEE 16.06.2025Published in Proceedings (IEEE Computer Security Foundations Symposium) (16.06.2025)“… The extension is practically popular, supported by many regex engines including those in the standard libraries of Java, Python, JavaScript, and more, and is also known to possess interesting…”
Get full text
Conference Proceeding -
19
PatchFuzz: Patch Fuzzing for JavaScript Engines
ISSN: 2331-8422Published: Ithaca Cornell University Library, arXiv.org 01.05.2025Published in arXiv.org (01.05.2025)“… While researchers have made efforts to apply patch fuzzing to testing JavaScript engines with considerable success, these efforts have been limited to using ordinary test cases or publicly available vulnerability PoCs (Proof of Concepts…”
Get full text
Paper -
20
Deity: Finding Deep Rooted Bugs in JavaScript Engines
ISSN: 2576-7828Published: IEEE 01.10.2019Published in Proceedings (International Conference on Communication Technology. Online) (01.10.2019)“…Fuzzing [1] is a well-known technique which was employed to provide unexpected or random data as input to JavaScript engines in hopes of finding a security vulnerability…”
Get full text
Conference Proceeding