/usr/5bin/su in SunOS 4.1.3 and earlier uses a search path that includes the current working directory (.), which allows local users to gain privileges via Trojan horse programs.
AV:L/AC:L/Au:N/C:C/I:C/A:C
This vulnerability has a 0.33% probability of being exploited in the next 30 days, ranking higher than 24% of all scored CVEs.