Unknown vulnerability in (1) loadmodule, and (2) modload if modload is installed with setuid/setgid privileges, in SunOS 4.1.1 through 4.1.3c, and Open Windows 3.0, allows local users to gain root privileges via environment variables, a different vulnerability than CVE-1999-1586.
Buffer overflow in CDE Calendar Manager Service Daemon (rpc.cmsd).
Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).
NFS cache poisoning.
Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.