GNU Enscript 1.6.1 and earlier allows local users to overwrite arbitrary files of the Enscript user via a symlink attack on temporary files.
When using the LDPRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.
The tmpwatch utility in Red Hat Linux forks a new process for each directory level, which allows local users to cause a denial of service by creating deeply nested directories in /tmp or /var/tmp/.
Vulnerability in Mandrake Linux usermode package allows local users to to reboot or halt the system.
Linux OpenLDAP server allows local users to modify arbitrary files via a symlink attack.
X fontserver xfs allows local users to cause a denial of service via malformed input to the server.
The X font server xfs in Red Hat Linux 6.x allows an attacker to cause a denial of service via a malformed request.
Linux printtool sets the permissions of printer configuration files to be world-readable, which allows local attackers to obtain printer share passwords.
Linux gpm program allows local users to cause a denial of service by flooding the /dev/gpmctl device with STREAM sockets.