https://www.cvedetails.com/vulnerability-search.php?f=1&prod... finds quite a few: double free, array out of bounds, buffer overflows in the stack and the heap…
There's also a format string vulnerability that wouldn't exist in Rust and which C turns into privilege escalation instead of aborting.