tar src/extract.c: delayed_link uses strcpy into tail buffer

wget vms_getpwuid-like function uses unchecked strcpy into fixed buffers (potential overflow)

wget: possible stack buffer overflow in NTLM base64 decode allocation

wget src/vms.c: potential stack/global buffer overflow via strcpy into fixed-size VMS buffers