{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,18]],"date-time":"2026-08-18T01:44:47Z","timestamp":1787017487784,"version":"build-2736575974"},"publisher-location":"New York, NY, USA","reference-count":96,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,10,10]],"date-time":"2022-10-10T00:00:00Z","timestamp":1665360000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,10,10]]},"DOI":"10.1145\/3551349.3556921","type":"proceedings-article","created":{"date-parts":[[2023,1,5]],"date-time":"2023-01-05T20:43:54Z","timestamp":1672951434000},"page":"1-13","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":14,"title":["Insight: Exploring Cross-Ecosystem Vulnerability Impacts"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8645-4326","authenticated-orcid":false,"given":"Meiqiu","family":"Xu","sequence":"first","affiliation":[{"name":"Software College, Northeastern University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ying","family":"Wang","sequence":"additional","affiliation":[{"name":"Software College, Northeastern University, China and Department of Computer Science and Engineering, The Hong Kong University of Science and Technology, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3508-7172","authenticated-orcid":false,"given":"Shing-Chi","family":"Cheung","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, The Hong Kong University of Science and Technology, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hai","family":"Yu","sequence":"additional","affiliation":[{"name":"Software College, Northeastern University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhiliang","family":"Zhu","sequence":"additional","affiliation":[{"name":"Software College, Northeastern University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,1,5]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2022. Arch Linux. https:\/\/archlinux.org\/. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_2_1","unstructured":"2022. Arch Linux Security. https:\/\/security.archlinux.org\/issues\/all. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_3_1","unstructured":"2022. Ble-driver. https:\/\/github.com\/NordicSemiconductor\/pc-ble-driver-py. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_4_1","unstructured":"2022. CFFI. https:\/\/cffi.readthedocs.io\/en\/latest\/. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_5_1","unstructured":"2022. CFlow is part of the GNU project which analyzes a collection of C source files and prints the call chains between functions.https:\/\/savannah.gnu.org\/projects\/cflow\/. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_6_1","volume-title":"Ctags tool","unstructured":"2022. Ctags tool. http:\/\/ctags.sourceforge.net\/. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_7_1","unstructured":"2022. Ctypes. https:\/\/docs.python.org\/3\/library\/ctypes.html. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_8_1","unstructured":"2022. CVE-2016-2073. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2016-2073. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_9_1","unstructured":"2022. CVE-2016-3627. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2016-3627. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_10_1","unstructured":"2022. CVE-2017-5029. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-5029. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_11_1","unstructured":"2022. CVE-2018-15686. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2018-15686. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_12_1","unstructured":"2022. CVE-2018-18557. https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-18557. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_13_1","unstructured":"2022. CVE-2019-11068. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-11068. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_14_1","unstructured":"2022. CVE-2019-17543. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-17543. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_15_1","unstructured":"2022. Cython. https:\/\/cython.readthedocs.io\/en\/latest\/src\/tutorial\/clibraries.html. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_16_1","unstructured":"2022. Debian. https:\/\/www.debian.org\/. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_17_1","unstructured":"2022. Debian Security. https:\/\/lists.debian.org\/debian-security-announce\/. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_18_1","unstructured":"2022. Dependabot. https:\/\/github.com\/dependabot. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_19_1","unstructured":"2022. Eclipse\/Sumo. https:\/\/www.eclipse.org\/sumo\/. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_20_1","unstructured":"2022. Emodb. https:\/\/github.com\/bazaarvoice\/emodb. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_21_1","unstructured":"2022. FFmpeg. https:\/\/ffmpeg.org\/. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_22_1","unstructured":"2022. The forwarded issue report in Linux community. https:\/\/github.com\/pypa\/manylinux\/issues\/1302. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_23_1","unstructured":"2022. Guidelines for naming C libraries. https:\/\/tldp.org\/HOWTO\/Program-Library-HOWTO\/shared-libraries.html#AEN46. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_24_1","unstructured":"2022. Hdf5. https:\/\/www.hdfgroup.org\/solutions\/hdf5. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_25_1","unstructured":"2022. Issue#1046 of KLayout. https:\/\/github.com\/KLayout\/klayout\/issues\/1046. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_26_1","unstructured":"2022. Issue#118 of Stratega. https:\/\/github.com\/GAIGResearch\/Stratega\/issues\/118. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_27_1","unstructured":"2022. Issue#135 of cython-hidapi. https:\/\/github.com\/trezor\/cython-hidapi\/issues\/135. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_28_1","unstructured":"2022. Issue#14623 of Incubator. https:\/\/github.com\/apache\/incubator-mxnet\/pull\/14623. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_29_1","unstructured":"2022. Issue#15 of Archi. https:\/\/github.com\/whtsky\/archi\/issues\/15. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_30_1","unstructured":"2022. Issue#167 of Etlflow. https:\/\/github.com\/tharwaninitin\/etlflow\/issues\/167. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_31_1","unstructured":"2022. Issue#171 of ParallelSSH. https:\/\/github.com\/ParallelSSH\/ssh2-python\/issues\/171. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_32_1","unstructured":"2022. Issue#199 of Xmlstarlet. https:\/\/github.com\/dimitern\/xmlstarlet\/issues\/199. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_33_1","unstructured":"2022. Issue#54 of Pyhdf. https:\/\/github.com\/fhs\/pyhdf\/issues\/54. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_34_1","unstructured":"2022. Issue#6 of Scalismo. https:\/\/github.com\/unibas-gravis\/scalismo-native\/issues\/6. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_35_1","volume-title":"Java Native Access(JNA)","unstructured":"2022. Java Native Access(JNA). http:\/\/java-native-access.github.io\/jna\/5.10.0\/javadoc\/overview-summary.html. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_36_1","unstructured":"2022. Java Native Interface(JNI). https:\/\/docs.oracle.com\/en\/java\/javase\/17\/docs\/specs\/jni\/index.html. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_37_1","unstructured":"2022. Libgit2. https:\/\/libgit2.org\/. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_38_1","unstructured":"2022. Libraries.io. https:\/\/libraries.io\/. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_39_1","unstructured":"2022. Maven. https:\/\/maven.apache.org\/. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_40_1","unstructured":"2022. Mongodb. https:\/\/www.mongodb.com\/. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_41_1","unstructured":"2022. Pdftopng. https:\/\/github.com\/vinayak-mehta\/pdftopng. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_42_1","unstructured":"2022. Pillow. https:\/\/github.com\/python-pillow\/Pillow. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_43_1","unstructured":"2022. Pip. https:\/\/packaging.python.org\/en\/latest\/key_projects\/#pip. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_44_1","unstructured":"2022. PyAV. https:\/\/github.com\/PyAV-Org\/PyAV\/. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_45_1","unstructured":"2022. RocksDB. https:\/\/github.com\/facebook\/rocksdb. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_46_1","unstructured":"2022. Scalismo. https:\/\/github.com\/unibas-gravis\/scalismo-native. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_47_1","unstructured":"2022. SWIG. https:\/\/swig.org\/. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_48_1","unstructured":"2022. Swiglpk. https:\/\/pypi.org\/project\/swiglpk\/. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_49_1","unstructured":"2022. Systemd. https:\/\/systemd.io\/. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_50_1","unstructured":"2022. Ubuntu. https:\/\/ubuntu.com\/. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_51_1","unstructured":"2022. Ubuntu Security. https:\/\/ubuntu.com\/security\/cve. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_52_1","unstructured":"2022. Vtk. https:\/\/vtk.org\/. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_53_1","unstructured":"2022. Wheel unpack. https:\/\/wheel.readthedocs.io\/en\/stable\/reference\/wheel_unpack.html. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_54_1","unstructured":"2022. Zipfile. https:\/\/docs.python.org\/zh-cn\/3\/library\/zipfile.html. (2022). Accessed: 2022-03-01."},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/3106237.3106267"},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/3379597.3387508"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/3432690"},{"key":"e_1_3_2_1_58_1","volume-title":"Too Quiet in the Library: An Empirical Study of Security Updates in Android Apps\u2019 Native Code. In 2021 IEEE\/ACM 43rd International Conference on Software Engineering (ICSE). IEEE, 1347\u20131359","author":"Almanee Sumaya","year":"2021","unstructured":"Sumaya Almanee, Arda \u00dcnal, Mathias Payer, and Joshua Garcia. 2021. Too Quiet in the Library: An Empirical Study of Security Updates in Android Apps\u2019 Native Code. In 2021 IEEE\/ACM 43rd International Conference on Software Engineering (ICSE). IEEE, 1347\u20131359."},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-020-09932-6"},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2018.2855650"},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASEW.2015.21"},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1145\/2950290.2950325"},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1109\/SANER.2015.7081868"},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1145\/3436877"},{"key":"e_1_3_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-021-09951-x"},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2015.140"},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1109\/SANER.2017.7884604"},{"key":"e_1_3_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.1145\/3196398.3196401"},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-017-9589-y"},{"key":"e_1_3_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2009.04.013"},{"key":"e_1_3_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134048"},{"key":"e_1_3_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1109\/TR.2019.2956690"},{"key":"e_1_3_2_1_73_1","volume-title":"Dependency smells in Javascript projects","author":"Jafari Abbas\u00a0Javan","year":"2021","unstructured":"Abbas\u00a0Javan Jafari, Diego\u00a0Elias Costa, Rabe Abdalkareem, Emad Shihab, and Nikolaos Tsantalis. 2021. Dependency smells in Javascript projects. IEEE Transactions on Software Engineering(2021)."},{"key":"e_1_3_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.13"},{"key":"e_1_3_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.62"},{"key":"e_1_3_2_1_76_1","unstructured":"Raula\u00a0Gaikovina Kula Ali Ouni Daniel\u00a0M German and Katsuro Inoue. 2017. On the impact of micro-packages: An empirical study of the npm javascript ecosystem. arXiv preprint arXiv:1709.04638(2017)."},{"key":"e_1_3_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1145\/3324884.3416558"},{"key":"e_1_3_2_1_78_1","volume-title":"Qualitative inquiry and research design: Choosing among five approaches. Health promotion practice 16, 4","author":"Lewis Sarah","year":"2015","unstructured":"Sarah Lewis. 2015. Qualitative inquiry and research design: Choosing among five approaches. Health promotion practice 16, 4 (2015), 473\u2013475."},{"key":"e_1_3_2_1_79_1","unstructured":"Chaoran Li Xiao Chen Ruoxi Sun Jason Xue Sheng Wen Muhammad\u00a0Ejaz Ahmed Seyit Camtepe and Yang Xiang. 2021. NatiDroid: Cross-Language Android Permission Specification. arXiv preprint arXiv:2111.08217(2021)."},{"key":"e_1_3_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSR.2017.60"},{"key":"e_1_3_2_1_81_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-19125-1_15"},{"key":"e_1_3_2_1_82_1","doi-asserted-by":"publisher","DOI":"10.1109\/MS.2014.81"},{"key":"e_1_3_2_1_83_1","doi-asserted-by":"publisher","DOI":"10.1145\/3239235.3268920"},{"key":"e_1_3_2_1_84_1","unstructured":"Ivan Pashchenko H. Plate Serena\u00a0Elisa Ponta Antonino Sabetta and F. Massacci. 2020. Vuln4Real: A Methodology for Counting Actually Vulnerable Dependencies. IEEE Transactions on Software Engineering(2020) 1\u20131."},{"key":"e_1_3_2_1_85_1","doi-asserted-by":"publisher","DOI":"10.1145\/1858996.1859089"},{"key":"e_1_3_2_1_86_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICST.2019.00017"},{"key":"e_1_3_2_1_87_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSM.2015.7332492"},{"key":"e_1_3_2_1_88_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSME.2018.00054"},{"key":"e_1_3_2_1_89_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460319.3464821"},{"key":"e_1_3_2_1_90_1","doi-asserted-by":"publisher","DOI":"10.1145\/3468264.3468541"},{"key":"e_1_3_2_1_91_1","doi-asserted-by":"publisher","DOI":"10.1145\/3180155.3180209"},{"key":"e_1_3_2_1_92_1","doi-asserted-by":"publisher","DOI":"10.1145\/2901739.2901743"},{"key":"e_1_3_2_1_93_1","volume-title":"TRACER: Finding Patches for Open Source Software Vulnerabilities. arXiv preprint arXiv:2112.02240(2021).","author":"Xu Congying","year":"2021","unstructured":"Congying Xu, Bihuan Chen, Chenhao Lu, Kaifeng Huang, Xin Peng, and Yang Liu. 2021. TRACER: Finding Patches for Open Source Software Vulnerabilities. arXiv preprint arXiv:2112.02240(2021)."},{"key":"e_1_3_2_1_94_1","volume-title":"International Conference on Software Maintenance and Evolution (ICSME). 559\u2013563","author":"Zapata Rodrigo\u00a0Elizalde","year":"2018","unstructured":"Rodrigo\u00a0Elizalde Zapata, Raula\u00a0Gaikovina Kula, Bodin Chinthanet, Takashi Ishio, Kenichi Matsumoto, and Akinori Ihara. 2018. Towards smoother library migrations: A look at vulnerable dependency migrations at function level for npm JavaScript packages. In International Conference on Software Maintenance and Evolution (ICSME). 559\u2013563."},{"key":"e_1_3_2_1_95_1","doi-asserted-by":"publisher","DOI":"10.1109\/SANER.2019.8667984"},{"key":"e_1_3_2_1_96_1","volume-title":"28th {USENIX} Security Symposium ({USENIX} Security 19). 995\u20131010.","author":"Zimmermann Markus","unstructured":"Markus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, and Michael Pradel. 2019. Small world with high risks: A study of security threats in the npm ecosystem. In 28th {USENIX} Security Symposium ({USENIX} Security 19). 995\u20131010."}],"event":{"name":"ASE '22: 37th IEEE\/ACM International Conference on Automated Software Engineering","location":"Rochester MI USA","acronym":"ASE '22"},"container-title":["Proceedings of the 37th IEEE\/ACM International Conference on Automated Software Engineering"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3551349.3556921","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3551349.3556921","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T08:32:38Z","timestamp":1755851558000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3551349.3556921"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,10,10]]},"references-count":96,"alternative-id":["10.1145\/3551349.3556921","10.1145\/3551349"],"URL":"https:\/\/doi.org\/10.1145\/3551349.3556921","relation":{},"subject":[],"published":{"date-parts":[[2022,10,10]]},"assertion":[{"value":"2023-01-05","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}