Out-of-bounds stack read in libidn before 1.33 in idna_to_ascii_4i (CVE-2016-6261).
Out-of-bounds-read in libidn when reading one zero byte as input (CVE-2015-8948, CVE-2016-6262).
In libidn before 1.33, stringprep_utf8_nfkc_normalize would crash when presented with invalid UTF-8 (CVE-2016-6263).