#CWE-120 clear

binutils opcodes/s390-mkopc.c: stack buffer overflow via strcpy/strcat into fixed 15-byte arrays

tar src/extract.c: delayed_link uses strcpy into tail buffer

tar: potential heap buffer overflow in lib/wordsplit.c when building VAR=value env strings

wget vms_getpwuid-like function uses unchecked strcpy into fixed buffers (potential overflow)

bash: possible heap buffer overflow via sprintf into xmalloc-sized buffer in bash_add_history

tar: potential buffer overflow via strcpy in lib/wordsplit.c env assignment

tar xheader.c uses strcpy/strcat with TMPDIR leading to buffer overflow (CWE-120)