Integer overflow in the searchfs system call in Mac OS X 10.3.9 and earlier allows local users to execute arbitrary code via crafted parameters.
http://www.kb.cert.org/vuls/id/185702
http://lists.apple.com/archives/security-announce/2005/Apr/msg00000.html