GNU tar follows symlinks blindly, a problem if you untar as root.
600ae24fbc5281fc8a5b4b3c636d3903Redhat rpc.statdx mass exploit - scans for vulnerable hosts and implants a bindshell.
cac3eaee702ca738d65e56d47813af1fFastgraf's whois.cgi perl script lacks meta character checking, allowing remote users to execute arbitrary commands as uid of the webserver.
ea926901a6a2bcf609f547f5d7968695Georgi Guninski security advisory #31 - There is a security vulnerability in Windows Media Player 7 exploitable thru IE which allows reading local files and executing arbitrary programs. The problem is the WMP ActiveX Control which allows launching javascript URLs in arbitrary already open frames. This allows taking over the frame's DOM. Includes exploit code. Demonstration available here.
bd37b33afb22c4facab4302296179eecXgtk.c is a local exploit for any set*id program which use Gtk+ up to v1.2.8. Uses the GTK_MODULES environment variable to trick gtk into executing arbitrary commands contained in a bogus module.
0fd07dc3c51acefce8bf0ccd612371ad