UnixWare pkgtrans allows local users to read arbitrary files via a symlink attack.
pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.
Command execution in Sun systems via buffer overflow in the at program.
Local user gains root privileges via buffer overflow in rdist, via lookup() function.
DNS cache poisoning via BIND, by predictable query IDs.
FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.
Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.
Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.