Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Description

OSS-Fuzz provides ongoing fuzz testing for open source applications, a method renowned for identifying programming flaws. Such flaws, including buffer overflow vulnerabilities, can pose significant security risks. Through the implementation of guided in-process fuzzing on Chrome components, Google has discovered thousands of security weaknesses and stability issues, and now aims to extend this beneficial service to the open source community. The primary objective of OSS-Fuzz is to enhance the security and stability of frequently used open source software by integrating advanced fuzzing methodologies with a scalable and distributed framework. For projects that are ineligible for OSS-Fuzz, there are alternatives available, such as running personal instances of ClusterFuzz or ClusterFuzzLite. At present, OSS-Fuzz is compatible with languages including C/C++, Rust, Go, Python, and Java/JVM, with the possibility of supporting additional languages that are compatible with LLVM. Furthermore, OSS-Fuzz facilitates fuzzing for both x86_64 and i386 architecture builds, ensuring a broad range of applications can benefit from this innovative testing approach. With this initiative, we hope to build a safer software ecosystem for all users.

Description

Jazzer, created by Code Intelligence, is a coverage-guided fuzzer designed for the JVM platform that operates within the process. It draws inspiration from libFuzzer, incorporating several of its advanced mutation features powered by instrumentation into the JVM environment. Users can explore Jazzer's autofuzz mode via Docker, which autonomously produces arguments for specified Java functions while also identifying and reporting any unexpected exceptions and security vulnerabilities that arise. Additionally, individuals can utilize the standalone Jazzer binary available in GitHub release archives, which initiates its own JVM specifically tailored for fuzzing tasks. This flexibility allows developers to effectively test their applications for robustness against various edge cases.

API Access

Has API No 

API Access

Has API No 

Screenshots View All

Screenshots View All

Integrations

Java Yes 
Atheris Yes 
C Yes 
C++ Yes 
ClusterFuzz Yes 
Docker No 
GitHub Yes 
Go Yes 
Google Cloud Storage Yes 
Kotlin No 
LibFuzzer No 
Python Yes 
Rust Yes 

Integrations

Java Yes 
Atheris No 
C No 
C++ No 
ClusterFuzz No 
Docker Yes 
GitHub No 
Go No 
Google Cloud Storage No 
Kotlin Yes 
LibFuzzer Yes 
Python No 
Rust No 

Pricing Details

Free
Free Trial No 
Free Version Yes 

Pricing Details

Free
Free Trial No 
Free Version Yes 

Deployment

Web-Based No 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows Yes 
Mac Yes 
Linux Yes 
Chromebook No 

Deployment

Web-Based No 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows Yes 
Mac Yes 
Linux Yes 
Chromebook No 

Customer Support

Business Hours No 
Live Rep (24/7) No 
Online Support Yes 

Customer Support

Business Hours No 
Live Rep (24/7) No 
Online Support Yes 

Types of Training

Training Docs Yes 
Webinars No 
Live Training (Online) No 
In Person No 

Types of Training

Training Docs Yes 
Webinars Yes 
Live Training (Online) Yes 
In Person Yes 

Vendor Details

Company Name

Google

Country

United States

Website

github.com/google/oss-fuzz

Vendor Details

Company Name

Code Intelligence

Country

Germany

Website

github.com/CodeIntelligenceTesting/jazzer

Product Features

Product Features

Alternatives

ClusterFuzz Reviews

ClusterFuzz

Google

Alternatives

Atheris Reviews

Atheris

Google
LibFuzzer Reviews

LibFuzzer

LLVM Project
LibFuzzer Reviews

LibFuzzer

LLVM Project
go-fuzz Reviews

go-fuzz

dvyukov
ToothPicker Reviews

ToothPicker

Secure Mobile Networking Lab