run-mozilla.sh in Thunderbird, with debugging enabled, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.
http://www.securityfocus.com/bid/14443
http://www.mandriva.com/security/advisories?name=MDKSA-2005:174
http://www.mandriva.com/security/advisories?name=MDKSA-2005:173
http://www.debian.org/security/2006/dsa-1051
http://www.debian.org/security/2006/dsa-1046