xfce4-settings could be made to run programs with arbitrary arguments if it received specially crafted input.