HP-UX aserver program allows local users to gain privileges via a symlink attack.
The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character).
Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.