CVE-2024-38428: URL parser hostname confusion via multiple @ characters in userinfo
CVE-2024-33869: Ghostscript path traversal via unresolved symlinks in SAFER mode
CVE-2023-43115: Ghostscript IJS device SAFER bypass allowing path traversal and arbitrary command execution
CVE-2023-43115: Ghostscript IJS device bypasses SAFER, allowing path-traversal arbitrary file write and RCE
CVE-2021-45944: Use-after-free in Ghostscript sampled_data_finish via moving GC interior-pointer invalidation
CVE-2020-15900: Ghostscript zbitshift integer overflow via off-by-one shift range check
CVE-2020-15900 — rsearch post-string size off-by-one in Ghostscript 9.52
Ghostscript CVE-2020-15900: Integer Overflow in PostScript Calculator bitshift Operator
Ghostscript CVE-2023-36664: Command Injection via Pipe Device Filename
GNU sed -i --follow-symlinks TOCTOU race → arbitrary file overwrite (CVE-2023-7008)
CVE-2023-7008: TOCTOU symlink race in sed --follow-symlinks
CVE-2022-28357: Heap buffer overflow in sed regex backreference handling
CVE-2013-0222: Buffer Overflow in coreutils sort via getmonth() with locale month names
CVE-2017-18018: TOCTOU race in coreutils chown/chgrp/chmod -R via symlink swap
CVE-2017-18018: TOCTOU Race Condition in coreutils chown with Symbolic Links to Special Files
CVE-2017-18018: TOCTOU race condition in coreutils chown -R -L (restricted_chown bypass)
CVE-2019-13636: GNU patch v2.7.6 symlink-following in create_file() allows writing to arbitrary files
CVE-2019-13636: Symlink-following vulnerability in GNU patch allows arbitrary file write