ftpd responds to the STAT command in a way that is not standards conformant. This could be used by a malicious party to corrupt state tables in firewall devices between an FTP client and a NetBSD FTP server.
getnetbyname and getnetbyaddr lacked important boundary checks, and are vulnerable to malicious DNS responses, which could cause a buffer overrun on the stack.
There is a buffer overflow in the processing of keyboard input by trek. On NetBSD 1.5 and prior, trek is executed via dm, so a malicious local user could elevate privilege to group "games".