Remote DoS with netfilter ipt_recent module. Privilege escalation with sendmsg() for amd64 platform. Reading kernel memory and IO ports with raw_sendmsg(). Memory leaks with procfs for SCSI drivers. USB DoS.
It's possible to bypass file scanning by using special characters (for example \01) in filename. Format string bug perenset while parsing filename in BitDefender.