Linux gpm program allows local users to cause a denial of service by flooding the /dev/gpmctl device with STREAM sockets.
The KApplication class in the KDE 1.1.2 configuration file management capability allows local users to overwrite arbitrary files.
makewhatis in Linux man package allows local users to overwrite files via a symlink attack.
The getdbm procedure in ypxfrd allows local users to read arbitrary files, and remote attackers to read databases outside /var/yp, via a directory traversal and symlink attack on the domain and map arguments.