rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.
The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.
Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges.
Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.
DNS cache poisoning via BIND, by predictable query IDs.
Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.
Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.