#cwe-120 clear

Unsafe font resource assembly in windres can overrun on long font strings

Binutils srconv output file name construction uses unbounded strcpy/strcat

tar: unsafe strcpy/strcat with environment-derived TMPDIR (xheader.c)