Double free vulnerability in the Widget Library (libxfcegui4) in Xfce before 4.4.2 might allow remote attackers to execute arbitrary code via unknown vectors related to the "cliend id, program name and working directory in session management."
http://www.xfce.org/documentation/changelogs/4.4.2
http://www.vupen.com/english/advisories/2008/0080