I can answer that I found CVE-2015-1789 twice with afl (through different input vectors) and a couple of other issues that were not security-relevant.
I'd assume that the null ptr pkcs#7 issue found by Michal Zalewski was also afl and the ecc issue as well (as documented by its founder). The CMS loop issue sounds also like it could've been found by fuzzing.
It's important to keep in mind what fuzzing can and can't do. It is a great method to find some bugs, but it has its limitations and can only find a certain class of bugs.