There's a security risk from ANY overflow.

If you can cause something to execute a peice of code, surley thats a security risk?

There's no privilege elevation involved here.
What says the code you ftp'd cant make an account with admin privilages??

If you have the code you can use any buffer overflow to execute it, providing you know where it is in memory- thats the security risk.