CVE-2024-2961: Buffer Overflow in glibc ISO-2022-CN-EXT iconv Converter
CVE-2024-2961: glibc iconv ISO-2022-CN-EXT encoder buffer overflow (TO_LOOP_MAX_NEEDED_TO underestimate)
CVE-2021-3999: glibc getcwd off-by-one buffer underflow/overflow (size==1)
CVE-2021-3999: glibc getcwd() off-by-one buffer underflow at filesystem root
CVE-2023-6779: glibc syslog heap overflow via long LogTag (bufsize scoping bug)
CVE-2023-6779: glibc __vsyslog_internal heap overflow via long openlog ident
CVE-2023-6779: glibc syslog heap-overflow through secondary buffer expansion
CVE-2023-6246: glibc __vsyslog_internal heap-overflow via undersized malloc in syslog fallback path
CVE-2023-6246: glibc syslog heap buffer overflow in __vsyslog_internal
CVE-2023-4911 Looney Tunables: heap buffer overflow in glibc parse_tunables via malformed GLIBC_TUNABLES
CVE-2023-4911 Looney Tunables Stack Buffer Overflow in glibc __tunables_init
CVE-2019-9924: bash rbash restricted-bypass via BASH_CMDS / assign_hashcmd
CVE-2019-9924: bash rbash escape via fall-back script interpretation and BASH_CMDS
CVE-2014-7169: Bash incomplete Shellshock fix — SEVAL_FUNCDEF bypassed via parser lookahead and line-continuation
CVE-2014-7169 — Bash Shellshock secondary injection via function-name parser interpolation
CVE-2014-7169: Shellshock secondary command-injection via invalid function identifiers
CVE-2019-18276: Bash restricted-bypass via enable builtin loading shared objects during startup
Bash CVE-2019-18276: Restricted Shell Bypass via Implicit Builtin Loading
CVE-2019-18276: bash disable_priv_mode leaks saved UID, exploitable via 'enable -f'
CVE-2014-6271: Shellshock - Function definition injection via environment variables