Uncovering Hidden Inclusions of Vulnerable Dependencies in Real-World Java Projects
Fuente:
arXiv
Saved in:
| Main Authors: | Schott, Stefan, Ponta, Serena Elisa, Fischer, Wolfram, Klauke, Jonas, Bodden, Eric |
|---|---|
| Format: | Preprint |
| Published: |
2026
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Bytecode-centric Detection of Known-to-be-vulnerable Dependencies in Java Projects
by: Schott, Stefan, et al.
Published: (2025)
by: Schott, Stefan, et al.
Published: (2025)
Compilation of Commit Changes within Java Source Code Repositories
by: Schott, Stefan, et al.
Published: (2024)
by: Schott, Stefan, et al.
Published: (2024)
A Soundness and Precision Benchmark for Java Debloating Tools
by: Klauke, Jonas, et al.
Published: (2025)
by: Klauke, Jonas, et al.
Published: (2025)
Beyond Metadata: Code-centric and Usage-based Analysis of Known Vulnerabilities in Open-source Software
by: Ponta, Serena E., et al.
Published: (2018)
by: Ponta, Serena E., et al.
Published: (2018)
Impact assessment for vulnerabilities in open-source software libraries
by: Plate, Henrik, et al.
Published: (2015)
by: Plate, Henrik, et al.
Published: (2015)
SourceBroken: A large-scale analysis on the (un)reliability of SourceRank in the PyPI ecosystem
by: Montaruli, Biagio, et al.
Published: (2025)
by: Montaruli, Biagio, et al.
Published: (2025)
Toward an Android Static Analysis Approach for Data Protection
by: Khedkar, Mugdha, et al.
Published: (2024)
by: Khedkar, Mugdha, et al.
Published: (2024)
Classport: Designing Runtime Dependency Introspection for Java
by: Cofano, Serena, et al.
Published: (2025)
by: Cofano, Serena, et al.
Published: (2025)
A Manually-Curated Dataset of Fixes to Vulnerabilities of Open-Source Software
by: Ponta, Serena E., et al.
Published: (2019)
by: Ponta, Serena E., et al.
Published: (2019)
From Detection to Prevention: Explaining Security-Critical Code to Avoid Vulnerabilities
by: Krishnamurthy, Ranjith, et al.
Published: (2026)
by: Krishnamurthy, Ranjith, et al.
Published: (2026)
Visualizing Privacy-Relevant Data Flows in Android Applications
by: Khedkar, Mugdha, et al.
Published: (2025)
by: Khedkar, Mugdha, et al.
Published: (2025)
FuzzySQL: Uncovering Hidden Vulnerabilities in DBMS Special Features with LLM-Driven Fuzzing
by: Chen, Yongxin, et al.
Published: (2026)
by: Chen, Yongxin, et al.
Published: (2026)
Proxion: Uncovering Hidden Proxy Smart Contracts for Finding Collision Vulnerabilities in Ethereum
by: Chen, Cheng-Kang, et al.
Published: (2024)
by: Chen, Cheng-Kang, et al.
Published: (2024)
Challenging Machine Learning Algorithms in Predicting Vulnerable JavaScript Functions
by: Ferenc, Rudolf, et al.
Published: (2024)
by: Ferenc, Rudolf, et al.
Published: (2024)
Real-World Usability of Vulnerability Proof-of-Concepts: A Comprehensive Study
by: Dang, Wenjing, et al.
Published: (2025)
by: Dang, Wenjing, et al.
Published: (2025)
Software Security Analysis in 2030 and Beyond: A Research Roadmap
by: Böhme, Marcel, et al.
Published: (2024)
by: Böhme, Marcel, et al.
Published: (2024)
PATCHEVAL: A New Benchmark for Evaluating LLMs on Patching Real-World Vulnerabilities
by: Wei, Zichao, et al.
Published: (2025)
by: Wei, Zichao, et al.
Published: (2025)
ContractTinker: LLM-Empowered Vulnerability Repair for Real-World Smart Contracts
by: Wang, Che, et al.
Published: (2024)
by: Wang, Che, et al.
Published: (2024)
A Large-scale Empirical Study on the Generalizability of Disclosed Java Library Vulnerability Exploits
by: Chen, Zirui, et al.
Published: (2026)
by: Chen, Zirui, et al.
Published: (2026)
Towards Understanding and Characterizing Vulnerabilities in Intelligent Connected Vehicles through Real-World Exploits
by: Wang, Yuelin, et al.
Published: (2026)
by: Wang, Yuelin, et al.
Published: (2026)
Uncover the Premeditated Attacks: Detecting Exploitable Reentrancy Vulnerabilities by Identifying Attacker Contracts
by: Yang, Shuo, et al.
Published: (2024)
by: Yang, Shuo, et al.
Published: (2024)
APPATCH: Automated Adaptive Prompting Large Language Models for Real-World Software Vulnerability Patching
by: Nong, Yu, et al.
Published: (2024)
by: Nong, Yu, et al.
Published: (2024)
Detecting Protracted Vulnerabilities in Open Source Projects
by: Sridharkumar, Arjun, et al.
Published: (2026)
by: Sridharkumar, Arjun, et al.
Published: (2026)
Insecure Ingredients? Exploring Dependency Update Patterns of Bundled JavaScript Packages on the Web
by: Swierzy, Ben, et al.
Published: (2025)
by: Swierzy, Ben, et al.
Published: (2025)
Profile of Vulnerability Remediations in Dependencies Using Graph Analysis
by: Vera, Fernando, et al.
Published: (2024)
by: Vera, Fernando, et al.
Published: (2024)
An Empirical Study of Vulnerable Package Dependencies in LLM Repositories
by: Liu, Shuhan, et al.
Published: (2025)
by: Liu, Shuhan, et al.
Published: (2025)
Does the Vulnerability Threaten Our Projects? Automated Vulnerable API Detection for Third-Party Libraries
by: Zhang, Fangyuan, et al.
Published: (2024)
by: Zhang, Fangyuan, et al.
Published: (2024)
A Comprehensive Study on the Impact of Vulnerable Dependencies on Open-Source Software
by: Kumar, Shree Hari Bittugondanahalli Indra, et al.
Published: (2025)
by: Kumar, Shree Hari Bittugondanahalli Indra, et al.
Published: (2025)
SAVANT: Vulnerability Detection in Application Dependencies through Semantic-Guided Reachability Analysis
by: Lingxiang, Wang, et al.
Published: (2025)
by: Lingxiang, Wang, et al.
Published: (2025)
Are Latent Vulnerabilities Hidden Gems for Software Vulnerability Prediction? An Empirical Study
by: Le, Triet H. M., et al.
Published: (2024)
by: Le, Triet H. M., et al.
Published: (2024)
The Code the World Depends On: A First Look at Technology Makers' Open Source Software Dependencies
by: Patrick, Cadence, et al.
Published: (2024)
by: Patrick, Cadence, et al.
Published: (2024)
From Trace to Line: LLM Agent for Real-World OSS Vulnerability Localization
by: Xi, Haoran, et al.
Published: (2025)
by: Xi, Haoran, et al.
Published: (2025)
R+R: Reassessing Java Security API Misuse in Current LLMs: A Replication on JCA and JSSE APIs with External Security Knowledge
by: Lu, Tianhe, et al.
Published: (2026)
by: Lu, Tianhe, et al.
Published: (2026)
PatchFuzz: Patch Fuzzing for JavaScript Engines
by: Wang, Junjie, et al.
Published: (2025)
by: Wang, Junjie, et al.
Published: (2025)
On the Effectiveness of Function-Level Vulnerability Detectors for Inter-Procedural Vulnerabilities
by: Li, Zhen, et al.
Published: (2024)
by: Li, Zhen, et al.
Published: (2024)
RealSec-bench: A Benchmark for Evaluating Secure Code Generation in Real-World Repositories
by: Wang, Yanlin, et al.
Published: (2026)
by: Wang, Yanlin, et al.
Published: (2026)
PPT4J: Patch Presence Test for Java Binaries
by: Pan, Zhiyuan, et al.
Published: (2023)
by: Pan, Zhiyuan, et al.
Published: (2023)
Maven-Lockfile: High Integrity Rebuild of Past Java Releases
by: Schmid, Larissa, et al.
Published: (2025)
by: Schmid, Larissa, et al.
Published: (2025)
KernJC: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities
by: Ruan, Bonan, et al.
Published: (2024)
by: Ruan, Bonan, et al.
Published: (2024)
Coverage-Guided Multi-Agent Harness Generation for Java Library Fuzzing
by: Loose, Nils, et al.
Published: (2026)
by: Loose, Nils, et al.
Published: (2026)
Similar Items
-
Bytecode-centric Detection of Known-to-be-vulnerable Dependencies in Java Projects
by: Schott, Stefan, et al.
Published: (2025) -
Compilation of Commit Changes within Java Source Code Repositories
by: Schott, Stefan, et al.
Published: (2024) -
A Soundness and Precision Benchmark for Java Debloating Tools
by: Klauke, Jonas, et al.
Published: (2025) -
Beyond Metadata: Code-centric and Usage-based Analysis of Known Vulnerabilities in Open-source Software
by: Ponta, Serena E., et al.
Published: (2018) -
Impact assessment for vulnerabilities in open-source software libraries
by: Plate, Henrik, et al.
Published: (2015)