{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:2DGD6S2DDJTWZS6IM5CYAY4DGT","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"760437507c8fca5afba6266b2998916124a5b223988567a131d2df4421253020","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by-sa/4.0/","primary_cat":"cs.SE","submitted_at":"2018-07-24T14:47:59Z","title_canon_sha256":"efede6d56125faeec61a00a61e736ca64f878570a2d026b5df9fde144ef00a15"},"schema_version":"1.0","source":{"id":"1807.09160","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1807.09160","created_at":"2026-05-18T00:09:56Z"},{"alias_kind":"arxiv_version","alias_value":"1807.09160v1","created_at":"2026-05-18T00:09:56Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1807.09160","created_at":"2026-05-18T00:09:56Z"},{"alias_kind":"pith_short_12","alias_value":"2DGD6S2DDJTW","created_at":"2026-05-18T12:31:59Z"},{"alias_kind":"pith_short_16","alias_value":"2DGD6S2DDJTWZS6I","created_at":"2026-05-18T12:31:59Z"},{"alias_kind":"pith_short_8","alias_value":"2DGD6S2D","created_at":"2026-05-18T12:31:59Z"}],"graph_snapshots":[{"event_id":"sha256:09af2ff264e8a0d558808f031b276796c69808e57a06f34ca59c552c41b3b1b2","target":"graph","created_at":"2026-05-18T00:09:56Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Testing is the most widely employed method to find vulnerabilities in real-world software programs. Compositional analysis, based on symbolic execution, is an automated testing method to find vulnerabilities in medium- to large-scale programs consisting of many interacting components. However, existing compositional analysis frameworks do not assess the severity of reported vulnerabilities. In this paper, we present a framework to analyze vulnerabilities discovered by an existing compositional analysis tool and assign CVSS3 (Common Vulnerability Scoring System v3.0) scores to them, based on va","authors_text":"Alexander Pretschner, Pooja Kulkarni, Ricardo Nales Amato, Saahil Ognawala","cross_cats":[],"headline":"","license":"http://creativecommons.org/licenses/by-sa/4.0/","primary_cat":"cs.SE","submitted_at":"2018-07-24T14:47:59Z","title":"Automatically Assessing Vulnerabilities Discovered by Compositional Analysis"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1807.09160","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:806336e380538f7bd46c4a1b12443689a7d16253fa28fa82ea9dea0769dd3941","target":"record","created_at":"2026-05-18T00:09:56Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"760437507c8fca5afba6266b2998916124a5b223988567a131d2df4421253020","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by-sa/4.0/","primary_cat":"cs.SE","submitted_at":"2018-07-24T14:47:59Z","title_canon_sha256":"efede6d56125faeec61a00a61e736ca64f878570a2d026b5df9fde144ef00a15"},"schema_version":"1.0","source":{"id":"1807.09160","kind":"arxiv","version":1}},"canonical_sha256":"d0cc3f4b431a676ccbc8674580638334e5600bb1b3c290d278c934566aefab41","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"d0cc3f4b431a676ccbc8674580638334e5600bb1b3c290d278c934566aefab41","first_computed_at":"2026-05-18T00:09:56.587879Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:09:56.587879Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"l3vQpeesHanOu5PUhISy6aHnXvm6DEX36Pnvrs6pVjKsfJr2uvoutCzCbWkNtt1dirlA+1Sg82j3Wa1u9+h+DA==","signature_status":"signed_v1","signed_at":"2026-05-18T00:09:56.588581Z","signed_message":"canonical_sha256_bytes"},"source_id":"1807.09160","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:806336e380538f7bd46c4a1b12443689a7d16253fa28fa82ea9dea0769dd3941","sha256:09af2ff264e8a0d558808f031b276796c69808e57a06f34ca59c552c41b3b1b2"],"state_sha256":"9d881cc624c4b33548cdab7750d871ab0b6df15323243cc78885bf0861f48a35"}