| 程序 | 漏洞类型 | 寻找方法 |
|---|---|---|
| accel-ppp | memory leak | Bleem |
| accel-ppp | stack-buffer-overflow | Bleem |
| boringssl | SIGPIPE | Bleem |
| webkit | NULL pointer dereference | Bleem |
| webkit | allocate big memory | Bleem |
| webkit | NULL pointer dereference | Bleem |
| webkit | NULL pointer dereference | Bleem |
| webkit | correctness issue | Bleem |
| webkit | NULL pointer dereference | Bleem |
| webkit | NULL pointer dereference | Bleem |
| webkit | heap-use-after-free | Bleem |
| webkit | heap-use-after-free | Bleem |
| webkit | NULL pointer dereference | Bleem |
| GridDB | pointer overflow | Unicorn |
| GridDB | pointer overflow | Unicorn |
| GridDB | implicit conversion | Unicorn |
| GridDB | implicit-integer-sign-change | Unicorn |
| GridDB | implicit conversion | Unicorn |
| GridDB | signed-integer-overflow | Unicorn |
| GridDB | assertion failure | Unicorn |
| GridDB | assertion failure | Unicorn |
| GridDB | assertion failure | Unicorn |
| GridDB | assertion failure | Unicorn |
| GridDB | SEGV | Unicorn |
| GridDB | memory leak | Unicorn |
| TimescaleDB | assertion failure | Unicorn |
| TimescaleDB | assertion failure | Unicorn |
| TimescaleDB | segmentation fault | Unicorn |
| TDengine | crash | Unicorn |
| TDengine | buffer overflow | Unicorn |
| TDengine | assertion failure | Unicorn |
| TDengine | segmentation fault | Unicorn |
| TDengine | hang out | Unicorn |
| TDengine | heap-buffer-overflow | Unicorn |
| QuestDB | infinite loop | Unicorn |
| QuestDB | invalid column exception | Unicorn |
| QuestDB | aggregation error | Unicorn |
| comdb2 | memory leak | Ratel |
| comdb2 | misaligned store | Ratel |
| comdb2 | misaligned load | Ratel |
| comdb2 | integer truncation | Ratel |
| comdb2 | integer truncation | Ratel |
| comdb2 | integer truncation | Ratel |
| comdb2 | misaligned load | Ratel |
| comdb2 | VLA misuse | Ratel |
| comdb2 | heap overflow | Ratel |
| comdb2 | buffer overflow | Ratel |
| comdb2 | integer overflow | Ratel |
| comdb2 | use-after-scope | Ratel |
| comdb2 | pointer misuse | Ratel |
| comdb2 | misaligned load | Ratel |
| comdb2 | integer truncation | Ratel |
| comdb2 | integer truncation | Ratel |
| comdb2 | buffer underflow | Ratel |
| comdb2 | misaligned load | Ratel |
| comdb2 | pointer misuse | Ratel |
| comdb2 | pointer misuse | Ratel |
| comdb2 | pointer misuse | Ratel |
| comdb2 | pointer misuse | Ratel |
| comdb2 | misaligned store | Ratel |
| comdb2 | misaligned store | Ratel |
| comdb2 | misaligned store | Ratel |
| comdb2 | misaligned store | Ratel |
| comdb2 | misaligned store | Ratel |
| comdb2 | misaligned load | Ratel |
| comdb2 | misaligned load | Ratel |
| comdb2 | misaligned load | Ratel |
| comdb2 | misaligned load | Ratel |
| comdb2 | misaligned load | Ratel |
| comdb2 | misaligned load | Ratel |
| comdb2 | misaligned load | Ratel |
| comdb2 | misaligned load | Ratel |
| comdb2 | integer truncation | Ratel |
| comdb2 | integer truncation | Ratel |
| comdb2 | integer truncation | Ratel |
| comdb2 | integer overflow | Ratel |
| comdb2 | integer truncation | Ratel |
| comdb2 | misaligned store | Ratel |
| comdb2 | misaligned store | Ratel |
| comdb2 | misaligned load | Ratel |
| comdb2 | misaligned load | Ratel |
| comdb2 | misaligned load | Ratel |
| comdb2 | integer truncation | Ratel |
| redis | pointer misuse | Ratel |
| redis | integer overflow | Ratel |
| redis | integer overflow | Ratel |
| redis | pointer misuse | Ratel |
| postgres | pointer misuse | Ratel |
| postgres | stack overflow | Ratel |
| postgres | memory leak | Ratel |
| postgres | memory leak | Ratel |
| postgres | integer truncation | Ratel |
| PostgreSQL | SEGV | Marmot |
| PostgreSQL | SEGV | Marmot |
| PostgreSQL | AF | Marmot |
| PostgreSQL | AF | Marmot |
| PostgreSQL | AF | Marmot |
| PostgreSQL | BOF | Marmot |
| MariaDB | SEGV | Marmot |
| MariaDB | SEGV | Marmot |
| MariaDB | SEGV | Marmot |
| MariaDB | SEGV | Marmot |
| MariaDB | AF | Marmot |
| MariaDB | UAP | Marmot |
| MariaDB | SEGV | Marmot |
| MariaDB | SEGV | Marmot |
| MariaDB | SEGV | Marmot |
| MariaDB | SEGV | Marmot |
| MariaDB | SEGV | Marmot |
| MariaDB | UAP | Marmot |
| MariaDB | SEGV | Marmot |
| MariaDB | SEGV | Marmot |
| MariaDB | AF | Marmot |
| MariaDB | use-after-free | Marmot |
| MariaDB | SEGV | Marmot |
| MariaDB | SEGV | Marmot |
| MariaDB | SEGV | Marmot |
| MariaDB | SEGV | Marmot |
| MariaDB | AF | Marmot |
| MariaDB | BOF | Marmot |
| MariaDB | UAP | Marmot |
| MariaDB | AF | Marmot |
| MariaDB | SEGV | Marmot |
| MariaDB | use-after-free | Marmot |
| MariaDB | UAP | Marmot |
| MariaDB | AF | Marmot |
| MariaDB | SEGV | Marmot |
| MariaDB | use-after-free | Marmot |
| MariaDB | SEGV | Marmot |
| MariaDB | SEGV | Marmot |
| MariaDB | AF | Marmot |
| MariaDB | UAP | Marmot |
| MariaDB | SEGV | Marmot |
| MariaDB | AF | Marmot |
| MariaDB | HUAF | Marmot |
| MariaDB | UAP | Marmot |
| MariaDB | UAP | Marmot |
| MariaDB | BOF | Marmot |
| MariaDB | UAP | Marmot |
| MariaDB | NULL pointer dereference | Marmot |
| MariaDB | BOF | Marmot |
| MariaDB | BOF | Marmot |
| MariaDB | NULL pointer dereference | Marmot |
| MySQL | AF | Marmot |
| MySQL | AF | Marmot |
| MysQL | AF | Marmot |
| MySQL | AF | Marmot |
| MySQL | use-after-free | Marmot |
| MySQL | AF | Marmot |
| MySQL | AF | Marmot |
| MySQL | AF | Marmot |
| MySQL | AF | Marmot |
| MySQL | AF | Marmot |
| MySQL | AF | Marmot |
| QuestDB | infinite loop | Unicorn |
| QuestDB | invalid column exception | Unicorn |
| QuestDB | aggregation error | Unicorn |
| GridDB | deadly signal | Unicorn |
| GridDB | memory leak | Unicorn |
| TimescaleDB | assertion failure | Unicorn |
| TimescaleDB | assertion failure | Unicorn |
| TimescaleDB | segmentation fault | Unicorn |
| TDengine | crashed | Unicorn |
| TDengine | overflow | Unicorn |
| TDengine | assertion failure | Unicorn |
| TDengine | segmentation fault | Unicorn |
| TDengine | hang out | Unicorn |
| TDengine | heap-buffer-overflow | Unicorn |
| loTDB | out of memory error | Unicorn |
| loTDB | storage engine failure exception | Unicorn |
| loTDB | number format exception | Unicorn |
| loTDB | binary cannot be cast to class java.lang.Float | Unicorn |
| loTDB | closed by interrupt exception | Unicorn |
| loTDB | NULL pointer exception | Unicorn |
| loTDB | NULL pointer exception | Unicorn |
| loTDB | transport exception | Unicorn |
| loTDB | index out of bounds exception | Unicorn |
| loTDB | check metadata error | Unicorn |
| loTDB | internal server error | Unicorn |
| loTDB | check metadata error | Unicorn |
| loTDB | class cast exception | Unicorn |
| loTDB | illegal path exception | Unicorn |
| loTDB | check metadata error | Unicorn |
| OpenDDS | heap-buffer-overflow | Jupiter |
| OpenDDS | heap-buffer-overflow | Jupiter |
| vsomeip | heap-buffer-overflow | PAVFuzz |
| IEC104 | SEGV | Polar |
| IEC104 | SEGV | Polar |
| IEC104 | SEGV | Polar |
| IEC104 | stack-buffer-overflow | Polar |
| FreeRTPS | global-buffer-overflow | Jupiter |
| FreeRTPS | global-buffer-overflow | Jupiter |
| FreeRTPS | global-buffer-overflow | Jupiter |
| FreeRTPS | stack-use-after-scope | Jupiter |
| Cyclone | heap-buffer-overflow | Jupiter |
| Cyclone | stack-buffer-overflow | Jupiter |
| OpenDDS | heap-buffer-overflow | Jupiter |
| OpenDDS | heap-buffer-overflow | Jupiter |
| OpenDDS | heap-buffer-overflow | Jupiter |
| libzmq | allocate-memory-failure | PAVFuzz |
| FastDDS | heap-buffer-overflow | PAVFuzz |
| FastDDS | stack-buffer-overflow | PAVFuzz |
| FastDDS | stack-buffer-overflow | PAVFuzz |
| FastDDS | stack-buffer-overflow | PAVFuzz |
| vsomeip | allocate-out-of-memory | PAVFuzz |
| vsomeip | heap-buffer-overflow | PAVFuzz |
| linux kernel v4.19 | inconsistent-lock-state | Healer |
| linux kernel v4.19 | kernel bug | Healer |
| linux kernel v4.19 | divide error | Healer |
| linux kernel v5.0 | deadlock | Healer |
| linux kernel v5.0 | deadlock | Healer |
| linux kernel v5.0 | out-of-bounds | Healer |
| linux kernel v5.0 | use-after-free | Healer |
| linux kernel v5.0 | out-of-bounds | Healer |
| linux kernel v5.6 | NULL pointer dereference | Healer |
| linux kernel v5.6 | data-race | Healer |
| linux kernel v5.6 | memory leak | Healer |
| linux kernel v5.6 | memory leak | Healer |
| linux kernel v5.6 | out-of-bounds | Healer |
| linux kernel v5.6 | uninit-value | Healer |
| linux kernel v5.11 | use-after-free | Healer |
| linux kernel v5.11 | data-race | Healer |
| linux kernel v5.11 | memory leak | Healer |
| linux kernel v5.11 | refcount bug | Healer |
| linux kernel v5.11 | general protection fault | Healer |
| linux kernel v5.11 | unable to handle paging request | Healer |
| linux kernel v5.11 | use-after-free | Healer |
| linux kernel v5.11 | data-race | Healer |
| linux kernel v5.11 | unable to handle paging request | Healer |
| linux kernel v5.11 | NULL pointer dereference | Healer |
| linux kernel v5.11 | data-race | Healer |
| linux kernelv5.11 | use-after-free | Healer |
| linux kernel v5.11 | data-race | Healer |
| linux kernel v5.11 | unable to handle paging request | Healer |
| linux kernel v5.11 | NULL pointer dereference | Healer |
| linux kernel v5.11 | data-race | Healer |
| linux kernel v5.11 | use-after-free | Healer |
| linux kernel v5.11 | shift-out-of-bounds | Healer |
| linux kernel v5.11 | data-race | Healer |
| CycloneDDs | heap-buffer-overflow | Peach* |
| CycloneDDS | stack-buffer-overflow | Peach* |
| IEC104 | SEGV | Polar |
| IEC104 | SEGV | Polar |
| IEC104 | stack-buffer-overflow | Polar |
| libiec_iccp_mod | heap-buffer-overflow | Peach* |
| libiec_iccp_mod | heap-buffer-overflow | Peach* |
| libiec_iccp_mod | heap-buffer-overflow | Peach* |
| libiec_iccp_mod | SEGV | Peach* |
| libmodbus | SEGV | Peach* |
| libmodbus | heap-use-after-free | Peach* |
| lib60870 | SEGV | Peach* |
| lib60870 | SEGV | Peach* |
| lib60870 | SEGV | Peach* |
| pdfalto | infinite loop | PAFL |
| pdfalto | SEGV | PAFL |
| pdfalto | SEGV | PAFL |
| pdfalto | FPE | PAFL |
| tinyrenderer | heap-buffer-overflow | PAFL |
| tinyrenderer | heap-buffer-overflow | PAFL |
| tinyrenderer | heap-buffer-overflow | PAFL |
| tinyrenderer | heap-buffer-overflow | PAFL |
| tinyrenderer | SEGV | PAFL |
| pdf2json | memory leaks | SAFL |
| sound | allocate failure | SAFL |
| pbc | SEGV | SAFL |
| pbc | SEGV | SAFL |
| THUNLP/Fast-TransX | SEGV | SAFL |
| THUNLP/Fast-Transx | SEGV | SAFL |
| THUNLP/Fast-TransX | SEGV | SAFL |
| THUNLP/NRE | SEGV | SAFL |
| THUNLP/NRE | SEGV | SAFL |
| parson | memory leaks | SAFL |
| word2vec | memory leaks | SAFL |
| inotify-tools | memory leaks | SAFL |
| lldb.rs | SEGV | SAFL |
| imgdataopt | SIGFPE | SAFL |
| libpng | memory leaks | SAFL |
| Bento4 | memory leaks | SAFL |
| Bento4 | memory leaks | SAFL |
| Bento4 | memory leaks | SAFL |
| doc2txt | heap-buffer-overflow | PAFL |
| astc-encoder | memory leak | SAFL |
| wav2json | assert failure | SAFL |
| sela | divide-by-zero error | SAFL |
| jpeg-compressor | negative-size-param | SAFL |
| jpeg-compressor | SEGV | SAFL |
| jpeg-compressor | global buffer overflow | SAFL |
| zcc | global buffer overflow | SAFL |
| htslib | SEGV | SAFL |
| rp | memory leak | SAFL |
| discount | memory leak | SAFL |
| pdffigures | segmentation fault | SAFL |
| MySQL | assertion failure | Marmot |
| MySQL | assertion failure | Marmot |
| DuckDB | heap-use-after-free | Marmot |
| ClickHouse | SEGV | Marmot |
| ClickHouse | SEGV | Marmot |
| ClickHouse | SEGV | Marmot |
| ClickHouse | SEGV | Marmot |
| ClickHouse | SEGV | Marmot |
| ClickHouse | SEGV | Marmot |
| ClickHouse | SEGV | Marmot |
| ClickHouse | SEGV | Marmot |
| ClickHouse | SEGV | Marmot |
| ClickHouse | SEGV | Marmot |
| ClickHouse | SEGV | Marmot |
| ClickHouse | SEGV | Marmot |
| ClickHouse | assertion failure | Marmot |
| ClickHouse | assertion failure | Marmot |
| Samba | FPE | BleemProtocol |