Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems.
The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which allows local attackers to conduct brute force password guessing.
Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.
Bash treats any character with a value of 255 as a command separator.