A buffer overflow exists in xli due to missing boundary checks. This could be triggered by an external attacker to execute commands on the victim's machine. An exploit is publically available.
A vulnerability was found by Salvatore Sanfilippo in both the IMAP and POP3 code of fetchmail where the input is not verified and no bounds checking is done.
An audit has been performed on the xinetd 2.3.0 source code by Solar Designer for many different possible vulnerabilities. The audit was very thorough and found and fixed many problems. This xinetd update includes his audit patch.
The iptables ip_conntrack_ftp module, which is used for stateful inspection of FTP traffic, does not validate parameters passed to it in an FTP PORT command.