The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which allows local attackers to conduct brute force password guessing.
Buffer overflow in University of Washington's implementation of IMAP and POP servers.
Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems.