...exploited: The vulnerability is caused due to a boundary error when handling the "SaveAs" function. On saving a maliciouspage with an overly long title (title tag in HTML), the program causes a stack-based overflow and makes it possible...
http://news.cnet.com/8301-1009_3-10034407-83.html