The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which allows local attackers to conduct brute force password guessing.
The (1) rcS and (2) mountall programs in Sun Solaris 2.x, possibly before 2.4, start a privileged shell on the system console if fsck fails while the system is booting, which allows attackers with physical access to gain root privileges.
Buffer overflow in Solaris dtprintinfo program.
The Sun sdtcmconvert calendar utility for OpenWindows has a buffer overflow which can gain root access.
In Solaris 2.2 and 2.3, when fsck fails on startup, it allows a local user with physical access to obtain root access.
The WorkMan program can be used to overwrite any file to get root access.
Solaris rpc.mountd generates error messages that allow a remote attacker to determine what files are on the server.
Local user gains root privileges via buffer overflow in rdist, via expstr() function.
Buffer overflow in ufsrestore in Solaris 8 and earlier allows local users to gain root privileges via a long pathname.
/opt/JSparm/bin/perfmon program in Solaris allows local users to create arbitrary files as root via the Logging File option in the GUI.