{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,22]],"date-time":"2026-07-22T16:46:32Z","timestamp":1784738792849,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":34,"publisher":"ACM","license":[{"start":{"date-parts":[[2009,11,9]],"date-time":"2009-11-09T00:00:00Z","timestamp":1257724800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2009,11,9]]},"DOI":"10.1145\/1653662.1653716","type":"proceedings-article","created":{"date-parts":[[2009,11,11]],"date-time":"2009-11-11T13:02:08Z","timestamp":1257944528000},"page":"442-452","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":51,"title":["Finding bugs in exceptional situations of JNI programs"],"prefix":"10.1145","author":[{"given":"Siliang","family":"Li","sequence":"first","affiliation":[{"name":"Lehigh University, Bethlehem, PA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Gang","family":"Tan","sequence":"additional","affiliation":[{"name":"Lehigh University, Bethlehem, PA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2009,11,9]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.5555\/829514.830533"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/372202.372786"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455778"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/586110.586142"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/512529.512538"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1007\/11693024_21"},{"key":"e_1_3_2_1_7_1","unstructured":"S. D. Gathman. java-posix. http:\/\/www.bmsi.com\/java\/posix\/package.html. Fetched on August 7 2009.  S. D. Gathman. java-posix. http:\/\/www.bmsi.com\/java\/posix\/package.html. Fetched on August 7 2009."},{"key":"e_1_3_2_1_8_1","volume-title":"http:\/\/java-gnome.sourceforge.net\/. Fetched on","year":"2009","unstructured":"The java-gnome user interface library. http:\/\/java-gnome.sourceforge.net\/. Fetched on August 7, 2009 . The java-gnome user interface library. http:\/\/java-gnome.sourceforge.net\/. Fetched on August 7, 2009."},{"key":"e_1_3_2_1_9_1","volume-title":"https:\/\/jogl.dev.java.net\/. Fetched on","author":"JOGL","year":"2009","unstructured":"JOGL API project. https:\/\/jogl.dev.java.net\/. Fetched on August 7, 2009 . JOGL API project. https:\/\/jogl.dev.java.net\/. Fetched on August 7, 2009."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.29"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/1390630.1390645"},{"key":"e_1_3_2_1_12_1","volume-title":"The Objective Caml system","author":"Leroy X.","year":"2008","unstructured":"X. Leroy . The Objective Caml system , 2008 . http:\/\/caml.inria.fr\/pub\/docs\/manual-ocaml\/index.html. X. Leroy. The Objective Caml system, 2008. http:\/\/caml.inria.fr\/pub\/docs\/manual-ocaml\/index.html."},{"key":"e_1_3_2_1_13_1","volume-title":"Java Native Interface: Programmer's Guide and Reference","author":"Liang S.","year":"1999","unstructured":"S. Liang . Java Native Interface: Programmer's Guide and Reference . Addison-Wesley Longman Publishing Co., Inc. , 1999 . S. Liang. Java Native Interface: Programmer's Guide and Reference. Addison-Wesley Longman Publishing Co., Inc., 1999."},{"key":"e_1_3_2_1_14_1","first-page":"271","volume-title":"14th Usenix Security Symposium","author":"Livshits B.","year":"2005","unstructured":"B. Livshits and M. Lam . Finding security vulnerabilities in Java applications with static analysis . In 14th Usenix Security Symposium , pages 271 -- 286 , 2005 . B. Livshits and M. Lam. Finding security vulnerabilities in Java applications with static analysis. In 14th Usenix Security Symposium, pages 271--286, 2005."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.5555\/2124243.2124258"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/1065887.1065892"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.5555\/647478.727796"},{"key":"e_1_3_2_1_18_1","volume-title":"Network and Distributed System Security Symposium(NDSS)","author":"Newsome J.","year":"2005","unstructured":"J. Newsome and D. Song . Dynamic taint analysis for automatic dedection, analysis, and signature generation of exploits on commodity software . In Network and Distributed System Security Symposium(NDSS) , 2005 . J. Newsome and D. Song. Dynamic taint analysis for automatic dedection, analysis, and signature generation of exploits on commodity software. In Network and Distributed System Security Symposium(NDSS), 2005."},{"key":"e_1_3_2_1_19_1","first-page":"372","volume-title":"In 20th IFIP International Information Security Conference","author":"A.","year":"2005","unstructured":"A. Nguyen-tuong, S. Guarnieri , D. Greene , and D. Evans . Automatically hardening web applications using precise tainting . In In 20th IFIP International Information Security Conference , pages 372 -- 382 , 2005 . A. Nguyen-tuong, S. Guarnieri, D. Greene, and D. Evans. Automatically hardening web applications using precise tainting. In In 20th IFIP International Information Security Conference, pages 372--382, 2005."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.5555\/555142"},{"key":"e_1_3_2_1_21_1","volume-title":"Apr.","author":"C","year":"2009","unstructured":"Python\/ C API reference manual. http:\/\/docs.python.org\/c-api\/index.html , Apr. 2009 . Python\/C API reference manual. http:\/\/docs.python.org\/c-api\/index.html, Apr. 2009."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/199448.199462"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/941566.941569"},{"key":"e_1_3_2_1_24_1","volume-title":"Retrieved Apr 26th, 2008","author":"Schoenefeld M.","year":"2003","unstructured":"M. Schoenefeld . Denial-of-service holes in JDK 1.3.1 and 1.4.1 01 . Retrieved Apr 26th, 2008 , from http:\/\/www.illegalaccess.org\/java\/ZipBugs.php, 2003 . M. Schoenefeld. Denial-of-service holes in JDK 1.3.1 and 1.4.1 01. Retrieved Apr 26th, 2008, from http:\/\/www.illegalaccess.org\/java\/ZipBugs.php, 2003."},{"key":"e_1_3_2_1_25_1","first-page":"201","volume-title":"In Proceedings of the 10th USENIX Security Symposium","author":"Shankar U.","year":"2001","unstructured":"U. Shankar , K. Talwar , J. S. Foster , and D. Wagner . Detecting format string vulnerabilities with type qualifiers . In In Proceedings of the 10th USENIX Security Symposium , pages 201 -- 220 , 2001 . U. Shankar, K. Talwar, J. S. Foster, and D. Wagner. Detecting format string vulnerabilities with type qualifiers. In In Proceedings of the 10th USENIX Security Symposium, pages 201--220, 2001."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.1986.6312929"},{"key":"e_1_3_2_1_27_1","first-page":"97","volume-title":"Proceedings of IEEE International Symposium on Secure Software Engineering","author":"Tan G.","year":"2006","unstructured":"G. Tan , A. W. Appel , S. Chakradhar , A. Raghunathan , S. Ravi , and D. Wang . Safe Java Native Interface . In Proceedings of IEEE International Symposium on Secure Software Engineering , pages 97 -- 106 , 2006 . G. Tan, A. W. Appel, S. Chakradhar, A. Raghunathan, S. Ravi, and D. Wang. Safe Java Native Interface. In Proceedings of IEEE International Symposium on Secure Software Engineering, pages 97--106, 2006."},{"key":"e_1_3_2_1_28_1","first-page":"365","volume-title":"17th Usenix Security Symposium","author":"Tan G.","year":"2008","unstructured":"G. Tan and J. Croft . An empirical security study of the native code in the JDK . In 17th Usenix Security Symposium , pages 365 -- 377 , 2008 . G. Tan and J. Croft. An empirical security study of the native code in the JDK. In 17th Usenix Security Symposium, pages 365--377, 2008."},{"key":"e_1_3_2_1_29_1","volume-title":"June","author":"CERT.","year":"2007","unstructured":"US- CERT. Vulnerability note VU#138545: Java Runtime Environment image parsing code buffer overflow vulnerability , June 2007 . Credit goes to Chris Evans . US-CERT. Vulnerability note VU#138545: Java Runtime Environment image parsing code buffer overflow vulnerability, June 2007. Credit goes to Chris Evans."},{"key":"e_1_3_2_1_30_1","volume-title":"Jan.","author":"CERT.","year":"2007","unstructured":"US- CERT. Vulnerability note VU#939609: Sun Java JRE vulnerable to arbitrary code execution via an unspecified error , Jan. 2007 . Credit goes to Chris Evans . US-CERT. Vulnerability note VU#939609: Sun Java JRE vulnerable to arbitrary code execution via an unspecified error, Jan. 2007. Credit goes to Chris Evans."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/1330017.1330019"},{"key":"e_1_3_2_1_32_1","first-page":"179","volume-title":"15th Usenix Security Symposium","author":"Xie Y.","year":"2006","unstructured":"Y. Xie and A. Aiken . Static detection of security vulnerabilities in scripting languages . In 15th Usenix Security Symposium , pages 179 -- 192 , Berkeley, CA, USA , 2006 . USENIX Association. Y. Xie and A. Aiken. Static detection of security vulnerabilities in scripting languages. In 15th Usenix Security Symposium, pages 179--192, Berkeley, CA, USA, 2006. USENIX Association."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2008.37"},{"key":"e_1_3_2_1_34_1","volume-title":"15th Usenix Security Symposium","author":"Xu W.","year":"2006","unstructured":"W. Xu , S. Bhatkar , and R. Sekar . Taint-enhanced policy enforcement: a practical approach to defeat a wide range of attacks . In 15th Usenix Security Symposium , Berkeley, CA, USA , 2006 . USENIX Association. W. Xu, S. Bhatkar, and R. Sekar. Taint-enhanced policy enforcement: a practical approach to defeat a wide range of attacks. In 15th Usenix Security Symposium, Berkeley, CA, USA, 2006. USENIX Association."}],"event":{"name":"CCS '09: 16th ACM Conference on Computer and Communications Security 2009","location":"Chicago Illinois USA","acronym":"CCS '09","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 16th ACM conference on Computer and communications security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1653662.1653716","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1653662.1653716","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T13:38:53Z","timestamp":1750253933000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1653662.1653716"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2009,11,9]]},"references-count":34,"alternative-id":["10.1145\/1653662.1653716","10.1145\/1653662"],"URL":"https:\/\/doi.org\/10.1145\/1653662.1653716","relation":{},"subject":[],"published":{"date-parts":[[2009,11,9]]},"assertion":[{"value":"2009-11-09","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}