
external_libexif_AOSP10_r33_CVE-2020-0198
C library for parsing, editing, and saving EXIF metadata, with a focus on addressing CVE-2020-0198 in AOSP10.

C library for parsing, editing, and saving EXIF metadata, with a focus on addressing CVE-2020-0198 in AOSP10.

C library for stream-oriented XML parsing with a focus on vulnerability analysis and exploitation of CVE-2022-43680, enabling fuzzing and…

Proof-of-concept exploit for CVE-2023-1999 targeting the WebP codec library on Android 10 (r33). Demonstrates a heap buffer overflow vulnerability in…

C library for parsing, editing, and saving EXIF data, with a focus on addressing CVE-2020-0452 in AOSP10. Provides API for metadata extraction and…

Exploit for CVE-2022-25173 targeting Jenkins Pipeline Groovy Plugin's CPS interpreter sandbox bypass, enabling arbitrary code execution within…

C library for stream-oriented XML parsing, with a focus on analyzing and reproducing CVE-2024-28757 vulnerability in Expat 2.1.0.

AI Code Security — four agents that catch what SAST misses in AI-generated code. Built on GitLab Duo Agent Platform.

C library for VP8/VP9 video encoding and decoding, with a focus on security patching for CVE-2023-5217.

Java library for XML serialization and deserialization, with a focus on CVE-2020-26217 exploitation. Enables converting Java objects to XML and back,…

a scenario based on CVE-2022-25845 yielding a TP for metadata based SCA but a FN if the callgraph is used

Created after the disclosure of CVE-2021-44228. Bash script that detects Log4j occurrences in your projects and systems, allowing you to get insight…

Created after the disclosure of CVE-2022-22965 and CVE-2022-22963. Bash script that detects Spring Framework occurrences in your projects and…

Secure coding project, research on CVE-2019-17498 and implement a player score function written in C.

// SPDX-FileCopyrightText: Portions Copyright 2021 Siemens // Modified on 15-Jul-2021 by Siemens and/or its affiliates to fix CVE-2018-1311: Apache…

Check with Maven on CVE-2011-1475

Skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize

A vulnerable version of Rails that follows the OWASP Top 10

LLVM based static binary analysis framework