CVE-2022-28357: Heap buffer overflow in sed regex backreference handling
CVE-2013-0222: Buffer Overflow in coreutils sort via getmonth() with locale month names
CVE-2017-18018: TOCTOU race in coreutils chown/chgrp/chmod -R via symlink swap
CVE-2017-18018: TOCTOU Race Condition in coreutils chown with Symbolic Links to Special Files
CVE-2017-18018: TOCTOU race condition in coreutils chown -R -L (restricted_chown bypass)
CVE-2019-13636: GNU patch v2.7.6 symlink-following in create_file() allows writing to arbitrary files
CVE-2019-13636: Symlink-following vulnerability in GNU patch allows arbitrary file write
CVE-2018-6952: GNU patch double-free in another_hunk via ptrn_missing+repl_missing
CVE-2019-13638: GNU patch shell injection via unquoted temp filename in do_ed_script()
CVE-2019-13638: GNU patch shell injection via popen() in do_ed_script
GNU patch CVE-2019-13638 - Shell injection via unquoted filenames in ed script
CVE-2022-2509: Double-free in GnuTLS find_signer() during PKCS7 cert chain verification
CVE-2022-2509: Double-free in GnuTLS certificate SAN extension parsing
CVE-2020-11501: GnuTLS STEK left zero on first use (TOTP gating skips initial rotation)
CVE-2020-11501: GnuTLS DTLS SRTP non-constant-time profile matching timing side-channel
CVE-2020-11501: Timing Side-Channel in GnuTLS DTLS SRTP Profile Negotiation
CVE-2021-20231 GnuTLS — Use-after-free via realloc-aliasing in TLS 1.3 client_hello extensions (key_share + pre_shared_key)
GnuTLS CVE-2021-20231: Use-After-Free in ECDHE Key Exchange Processing
CVE-2020-24659: GnuTLS NULL deref via no_renegotiation alert mid-handshake
GnuTLS CVE-2020-24659: NULL pointer dereference in session ticket extension handling