Hi, Chang,
My tool SAINT (https://github.com/xaviernoumbis/saint) implements a static taint
analysis that can be used to detect buffer overflows.
The draft of the paper can be find here:
https://sites.google.com/site/xaviernoumbis/research/noumbissi-draft-phd-thesis.pdf
Best Regards