
Web3Bugs
Demystifying Exploitable Bugs in Smart Contracts

Demystifying Exploitable Bugs in Smart Contracts

UT based automated fuzz driver generation

Pishi is a code coverage tool like kcov for macOS.

Fuzzing Framework for Modules in Apache HTTPD Server

Evidence-driven C/C++ vulnerability remediation pipeline + http-parser case study (CVE-2024-22019-class). Python core, React 19 console, 17-test…

A reverse engineering framework written in Python.

CVE-Candidate: DoS in [email protected] via comma-separated brace expansion (CVE-2024-4068 incomplete fix)

Trail of Bits Testing Handbook - appsec.guide

Security-oriented Go toolchain, focused on state-of-the-art fuzzing capabilities.

A coverage-guided fuzzer for pure Ruby code and Ruby C extensions

A lightweight dynamic instrumentation library

Out-Of-Bounds Read in html2xhtml : CVE-2022-44311

Security research project on fuzzing libpng with OSS-Fuzz. Includes seed corpus analysis, custom read/write fuzzers, and a proof-of-concept exploit…


Enhanced fuzzing for tmux using OSS-Fuzz. Includes custom `cmd-fuzzer` and `argument-fuzzer` harnesses for improved code coverage and a PoC for…
