Comment Re:Green Damn Exploit (Score 2, Informative) 63
http://www.cse.umich.edu/~jhalderm/pub/gd/
If this is to be believed (I haven't tried verifying it myself), then they've committed the most ancient web browser vulnerability I know of (accepting a URL into a fixed size buffer).