CPE
Freeciv versions prior to 3.2.6 contain a heap-based buffer overflow in the worklist_load() function that allows memory corruption via maliciously crafted savegame files.