Search Results - Vulnerable JavaScript
-
1
Vulnerable JavaScript functions detection using stacking of convolutional neural networks
ISSN: 2376-5992, 2376-5992Published: United States PeerJ. Ltd 29.02.2024Published in PeerJ. Computer science (29.02.2024)“…System security for web-based applications is paramount, and for the avoidance of possible cyberattacks it is important to detect vulnerable JavaScript functions…”
Get full text
Journal Article -
2
Challenging Machine Learning Algorithms in Predicting Vulnerable JavaScript Functions
Published: IEEE 01.05.2019Published in 2019 IEEE/ACM 7th International Workshop on Realizing Artificial Intelligence Synergies in Software Engineering (RAISE) (01.05.2019)“… in JavaScript programs. We applied 8 machine learning algorithms to build prediction models using a new dataset constructed for this research from the vulnerability information in public databases of the Node Security…”
Get full text
Conference Proceeding -
3
On the Impact of Outdated and Vulnerable Javascript Packages in Docker Images
Published: IEEE 01.02.2019Published in 2019 IEEE 26th International Conference on Software Analysis, Evolution and Reengineering (SANER) (01.02.2019)“…Containerized applications, and in particular Docker images, are becoming a common solution in cloud environments to meet ever-increasing demands in terms of…”
Get full text
Conference Proceeding -
4
A Protection Mechanism against Malicious HTML and JavaScript Code in Vulnerable Web Applications
ISSN: 1024-123X, 1563-5147Published: Cairo, Egypt Hindawi Publishing Corporation 01.01.2016Published in Mathematical problems in engineering (01.01.2016)“… and web browsers against malicious HTML and JavaScript code in vulnerable web applications…”
Get full text
Journal Article -
5
Challenging Machine Learning Algorithms in Predicting Vulnerable JavaScript Functions
ISSN: 2331-8422Published: Ithaca Cornell University Library, arXiv.org 12.05.2024Published in arXiv.org (12.05.2024)“… in JavaScript programs. We applied 8 machine learning algorithms to build prediction models using a new dataset constructed for this research from the vulnerability information in public databases of the Node Security…”
Get full text
Paper -
6
Towards Smoother Library Migrations: A Look at Vulnerable Dependency Migrations at Function Level for npm JavaScript Packages
ISSN: 2576-3148Published: IEEE 01.09.2018Published in 2018 IEEE International Conference on Software Maintenance and Evolution (ICSME) (01.09.2018)“…It has become common practice for software projects to adopt third-party libraries, allowing developers full access to functions that otherwise will take time…”
Get full text
Conference Proceeding -
7
PatchFuzz: Patch fuzzing for JavaScript engines
ISSN: 0950-5849Published: Elsevier B.V 01.06.2026Published in Information and software technology (01.06.2026)“… While researchers have made efforts to apply patch fuzzing to testing JavaScript (JS) engines with considerable success, these efforts have been limited to using ordinary test cases or publicly available vulnerability PoCs (Proof of Concepts…”
Get full text
Journal Article -
8
Detection of Obfuscated Malicious JavaScript Code
ISSN: 1999-5903, 1999-5903Published: Basel MDPI AG 01.08.2022Published in Future internet (01.08.2022)“…Websites on the Internet are becoming increasingly vulnerable to malicious JavaScript code because of its strong impact and dramatic effect…”
Get full text
Journal Article -
9
A client‐server JavaScript code rewriting‐based framework to detect the XSS worms from online social network
ISSN: 1532-0626, 1532-0634Published: Hoboken Wiley Subscription Services, Inc 10.11.2019Published in Concurrency and computation (10.11.2019)“…Summary This article presents a client‐server JavaScript code rewriting‐based framework that protects and preserves the privacy of online users against XSS worms on Online Social Network (OSN). The server…”
Get full text
Journal Article -
10
NodeXP: NOde.js server-side JavaScript injection vulnerability DEtection and eXPloitation
ISSN: 2214-2126Published: Elsevier Ltd 01.05.2021Published in Journal of information security and applications (01.05.2021)“…; Node.js is no exception, as Server-Side JavaScript Injection (SSJI) attacks are possible due to the use of vulnerable functions and neglecting to sanitize data input provided by untrusted sources…”
Get full text
Journal Article -
11
Towards a Prototype Based Explainable JavaScript Vulnerability Prediction Model
Published: IEEE 27.03.2021Published in 2021 International Conference on Code Quality (ICCQ) (27.03.2021)“…: explainability and granularity of predictions. In this paper, we propose a novel and simple yet, promising approach to identify potentially vulnerable source code in JavaScript programs…”
Get full text
Conference Proceeding -
12
A lightweight and high-precision approach for bulky JavaScript engines fuzzing
ISSN: 2324-9013Published: IEEE 01.11.2023Published in IEEE ... International Conference on Trust, Security and Privacy in Computing and Communications (Online) (01.11.2023)“… To improve the precision of coverage feedback and target the vulnerable JIT compiler of Javascript engines, we presented our fuzzer, called LF(Light Fuzzer…”
Get full text
Conference Proceeding -
13
Analysis of JavaScript Web Applications Using SAFE 2.0
Published: IEEE 01.05.2017Published in 2017 IEEE/ACM 39th International Conference on Software Engineering Companion (ICSE-C) (01.05.2017)“… However, because JavaScript and web environments are extremely dynamic, JavaScript web applications are often vulnerable to type-related errors and security attacks…”
Get full text
Conference Proceeding -
14
Detecting Malicious Javascript in PDF through Document Instrumentation
ISSN: 1530-0889Published: IEEE 01.06.2014Published in Proceedings - International Conference on Dependable Systems and Networks (01.06.2014)“… Owed to its wide-spread use and Javascript support, PDF has been the primary vehicle for delivering embedded exploits…”
Get full text
Conference Proceeding -
15
A Study of Vulnerability Repair in JavaScript Programs with Large Language Models
ISSN: 2331-8422Published: Ithaca Cornell University Library, arXiv.org 19.03.2024Published in arXiv.org (19.03.2024)“… We also investigate the impact of context in a prompt on directing LLMs to produce a correct patch of vulnerable JavaScript code…”
Get full text
Paper -
16
Real-Time Threat Detection with JavaScript: Monitoring and Response Mechanisms
ISSN: 2706-5847, 2707-9619Published: Zhytomyr Polytechnic State University 01.06.2024Published in Tehnìčna ìnženerìâ (01.06.2024)“… This article examines real-time threat detection, monitoring, and response techniques at the confluence of JavaScript and security…”
Get full text
Journal Article -
17
MFXSS: An effective XSS vulnerability detection method in JavaScript based on multi-feature model
ISSN: 0167-4048Published: Elsevier Ltd 01.01.2023Published in Computers & security (01.01.2023)“… Therefore, we proposed a multi-feature fusion-based neural network vulnerability detection model for detecting XSS vulnerabilities in the JavaScript source code of website…”
Get full text
Journal Article -
18
Challenges to JavaScript obfuscation in the era of large language models
ISSN: 2473-5698Published: IEEE 09.10.2025Published in International Conference on System Theory, Control and Computing (09.10.2025)“… The results reveal a critical insight-contemporary JavaScript obfuscation techniques are increasingly vulnerable to the capabilities of modern LLMs, highlighting the urgent need for more robust client-side code protection strategies…”
Get full text
Conference Proceeding -
19
SecBench.js: An Executable Security Benchmark Suite for Server-Side JavaScript
ISSN: 1558-1225Published: IEEE 01.05.2023Published in Proceedings / International Conference on Software Engineering (01.05.2023)“…NPM is the largest software ecosystem in the world, offering millions of free, reusable packages. In recent years, various security threats to packages…”
Get full text
Conference Proceeding -
20
Securing web-clients with instrumented code and dynamic runtime monitoring
ISSN: 0164-1212, 1873-1228Published: New York Elsevier Inc 01.06.2013Published in The Journal of systems and software (01.06.2013)“… ► Self-contained, in-browser security manager for the JavaScript Language. ► A collection of secure JavaScript equivalent objects…”
Get full text
Journal Article