Possible RCE via stack-based buffer overflow in the fmt_entry function (CVE-2017-10684).
Possible RCE with format string vulnerability in the fmt_entry function (CVE-2017-10685).
Illegal address access in append_acs (CVE-2017-11112).
Dereferencing NULL pointer in ncparse_entry (CVE-2017-11113).