Buffer overflows in Washington University imapd 2000a through 2000c could allow local users without shell access to execute code as themselves in certain configurations.
http://www.securityfocus.com/bid/2856
http://www.securityfocus.com/advisories/3352