inpview in SGI IRIX allows local users to execute arbitrary commands via the SUN_TTSESSION_CMD environment variable, which is executed by inpview without dropping privileges.
https://exchange.xforce.ibmcloud.com/vulnerabilities/18894
http://www.securityfocus.com/bid/12259
http://www.idefense.com/application/poi/display?id=182&type=vulnerabilities