binutils CVE-2023-1579: Heap overflow in COFF relocation handling due to incorrect reloc_count tracking
CVE-2021-3487: binutils readelf OOB read in fetch_indexed_string (.debug_str_offsets)
CVE-2021-3487: Integer underflow in DWARF string offset parsing leads to out-of-bounds read
CVE-2020-16592: use-after-free in bfd_hash_lookup (binutils 2.34 BFD library)
CVE-2020-16592: binutils libbfd UAF in section merging via hash table resize
CVE-2020-16592: Use-after-free in BFD merge.c during section merging
CVE-2022-38126: Memory leak in binutils bfd/dwarf2.c read_abbrevs — partial abbrev not freed on error, re-parsing loop
CVE-2022-38126: Memory leak in BFD DWARF abbreviation table handling
CVE-2017-8421: binutils objdump unbounded memory allocation via crafted ELF sh_size
CVE-2017-8421: Unbounded memory allocation in binutils relocation parsing
CVE-2022-38533: Heap overflow in BFD compressed section decompression
CVE-2016-6321: GNU tar path traversal via --strip-components applied after safer_name_suffix
tar CVE-2016-6321: Path-traversal via unvalidated --strip-components
CVE-2022-48303: GNU tar 1.34 heap-overflow via OOB read in from_header() base-256 parsing with leading spaces
CVE-2019-5953: wget heap buffer overflow in do_conversion via incorrect E2BIG handling
CVE-2019-5953: Buffer overflow in wget IRI character conversion
CVE-2021-31879: wget Authorization header leak on cross-origin redirect via --header
CVE-2021-31879: Wget Authorization Header Leak on Cross-Origin Redirects
CVE-2021-31879: Wget leaks Authorization header on cross-origin redirect
CVE-2018-20483: wget leaks URL credentials into POSIX extended file attributes (xattrs)