There is a buffer overflow vulnerability in the 'file' command's ELF parsing routines which can allow an attacker to exploit a victim by tricking them into running 'file' on a specially crafted binary.
Keigo Yamazaki discovered a vulnerability in miniserv.pl which may allow an attacker to spoof a session ID by including special metacharacters in the BASE64 encoded string using during the authentication process.