Ask.com says they’ve fixed a critical bug in their toolbar, discovered by Joey Mengele. The vulnerability is caused due to a boundary error in the AskJeevesToolBar.Settings plugin.1 ActiveX control (askBar.dll) When handling the “Short Format” property, the bug can be exploited to cause a stack-based buffer overflow by assigning an overly long (greater than 500 bytes) string to the affected property. Proof of concept code for this bug is still being offered on the WabiSabiLabi marketplace.”]
Source: https://www.csoonline.com/article/2136828/ask-com-fixes-toolbar-flaw.html