Buffer overflow in mhshow in the Linux nmh package allows remote attackers to execute commands via malformed MIME headers in an email message.
The mtr program only uses a seteuid call when attempting to drop privileges, which could allow local users to gain root privileges.
Buffer overflow in the man program in Linux allows local users to gain privileges via the MANPAGER environmental variable.
Red Hat userhelper program in the usermode package allows local users to gain root access via PAM and a .. (dot dot) attack.