An anonymous user can gain remote root access due to a buffer overflow caused by a StrnCpy() into a char array (fname) using a non-constant length (namelen).
There is a vulnerability in sendmail that can be exploited to cause a denial-of-service condition and could allow a remote attacker to execute arbitrary code with the privileges of the sendmail daemon, typically root.
A cryptographic weakness in version 4 of the Kerberos protocol allows anattacker to use a chosen-plaintext attack to impersonate any principal in arealm. OpenAFS kaserver implements version 4 of the Kerberos protocol, andtherefore is vulnerable.