binutils CVE-2023-1579: Heap overflow in COFF relocation handling due to incorrect reloc_count tracking
CVE-2021-3487: binutils readelf OOB read in fetch_indexed_string (.debug_str_offsets)
CVE-2021-3487: Integer underflow in DWARF string offset parsing leads to out-of-bounds read
CVE-2020-16592: binutils libbfd UAF in section merging via hash table resize
CVE-2020-16592: Use-after-free in BFD merge.c during section merging
CVE-2022-38126: Memory leak in binutils bfd/dwarf2.c read_abbrevs — partial abbrev not freed on error, re-parsing loop
CVE-2022-38126: Memory leak in BFD DWARF abbreviation table handling
CVE-2017-13089: wget skip_short_body stack overflow via negative HTTP chunk size (signed strtol + SIZE_MAX read)
CVE-2017-13089: wget skip_short_body() stack overflow via negative chunked size
CVE-2023-7008: TOCTOU symlink race in sed --follow-symlinks
CVE-2022-28357: Heap buffer overflow in sed regex backreference handling
CVE-2013-0222: Buffer Overflow in coreutils sort via getmonth() with locale month names
GNU patch CVE-2019-13638 - Shell injection via unquoted filenames in [redacted:name]
CVE-2022-2509: Double-free in GnuTLS find_signer() during PKCS7 cert chain verification
CVE-2022-2509: Double-free in GnuTLS certificate SAN extension parsing
CVE-2021-20231 GnuTLS — Use-after-free via realloc-aliasing in TLS 1.3 client_hello extensions (key_share + pre_shared_key)
GnuTLS CVE-2021-20231: Use-After-Free in ECDHE Key Exchange Processing
CVE-2020-24659: GnuTLS NULL deref via no_renegotiation alert mid-handshake