feh before 1.8, when the --wget-timestamp option is enabled, might allow remote attackers to execute arbitrary commands via shell metacharacters in a URL.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2010-2258
http://www.securityfocus.com/bid/41161
http://openwall.com/lists/oss-security/2010/06/28/4