The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.
The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.
Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.