The Guile plugin for the Gnumeric spreadsheet package allows malicious users to execute arbitrary code.
gnu gnumeric 0.27