CVE-2021-3518: Use-after-free in xmlXIncludeAddNode XInclude processing
CVE-2020-8177: curl -J -i interaction enables local-file overwrite via early fopen("wb")
CVE-2023-46218: curl cookie domain matching logic bug allows cross-domain leakage
CVE-2023-46218 curl cookie mixed-case PSL bypass in Curl_cookie_add
CVE-2023-27535: curl FTP connection reuse skips FTP_ACCOUNT / ALTERNATIVE_TO_USER / USE_SSL comparisons
CVE-2021-3487: binutils readelf OOB read in fetch_indexed_string (.debug_str_offsets)
CVE-2022-38126: Memory leak in binutils bfd/dwarf2.c read_abbrevs — partial abbrev not freed on error, re-parsing loop
CVE-2022-38126: Memory leak in BFD DWARF abbreviation table handling
CVE-2017-8421: binutils objdump unbounded memory allocation via crafted ELF sh_size
CVE-2021-31879: Wget leaks Authorization header on cross-origin redirect
CVE-2018-20483: wget leaks URL credentials into POSIX extended file attributes (xattrs)
CVE-2018-20483: wget --xattr leaks URL credentials into user.xdg.origin.url extended attribute
CVE-2024-38428: wget url_skip_credentials semicolon causes hostname confusion
CVE-2024-38428: GNU Wget url_skip_credentials mishandles ';' in userinfo, enabling hostname confusion
CVE-2024-38428: URL parser hostname confusion via multiple @ characters in userinfo
CVE-2024-33869: Ghostscript path traversal via unresolved symlinks in SAFER mode
CVE-2017-18018: TOCTOU Race Condition in coreutils chown with Symbolic Links to Special Files
CVE-2018-6952: GNU patch double-free in another_hunk via ptrn_missing+repl_missing
CVE-2022-2509: Double-free in GnuTLS certificate SAN extension parsing
CVE-2020-11501: GnuTLS DTLS SRTP non-constant-time profile matching timing side-channel