tar src/extract.c: delayed_link uses strcpy into tail buffer
wget vms_getpwuid-like function uses unchecked strcpy into fixed buffers (potential overflow)
wget: possible stack buffer overflow in NTLM base64 decode allocation
wget src/vms.c: potential stack/global buffer overflow via strcpy into fixed-size VMS buffers