RXVT-Unicode 3.4 and 3.5 does not properly close file descriptors, which allows local users to access the terminals of other users and possibly gain privileges.
https://exchange.xforce.ibmcloud.com/vulnerabilities/17000
http://www.securityfocus.com/bid/10959
http://secunia.com/advisories/12299
http://cvs.schmorp.de/browse/rxvt-unicode/Changes?view=markup