rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, which could provide supplemental group privileges to local users, who could then read certain files that would otherwise be disallowed.
Memory leak in SNMP in Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service.
GNU Enscript 1.6.1 and earlier allows local users to overwrite arbitrary files of the Enscript user via a symlink attack on temporary files.
Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary files via a symlink attack.
glibc 2.1.9x and earlier does not properly clear the RESOLVHOSTCONF, HOSTALIASES, or RESOPTIONS environmental variables when executing setuid/setgid programs, which could allow local users to read arbitrary files.
privatepw program in wu-ftpd before 2.6.1-6 allows local users to overwrite arbitrary files via a symlink attack.
vpop3d program in linuxconf 1.23r and earlier allows local users to overwrite arbitrary files via a symlink attack.
squid 2.3 and earlier allows local users to overwrite arbitrary files via a symlink attack in some configurations.
arpwatch 2.1a4 allows local users to overwrite arbitrary files via a symlink attack in some configurations.
gettyps 2.0.7j allows local users to overwrite arbitrary files via a symlink attack.
useradd program in shadow-utils program may allow local users to overwrite arbitrary files via a symlink attack.
sdiff 2.7 in the diffutils package allows local users to overwrite files via a symlink attack.
gpm 1.19.3 allows local users to overwrite arbitrary files via a symlink attack.
inn 2.2.3 allows local users to overwrite arbitrary files via a symlink attack in some configurations.
rdist 6.1.5 allows local users to overwrite arbitrary files via a symlink attack.
Linux tmpwatch --fuser option allows local users to execute arbitrary commands by creating files whose names contain shell metacharacters.