> Mixing data and code in the memory of a running program is what has lead us to every exploit involving a buffer overflow or a stack smash.
Not exactly. The totally unsafe programming model of C is what has caused this. Once you have untyped pointers that need not point to objects owned by your program, it is very easy to fuck something up.
> Lisp is not the only language that can build a string and throw it at an eval function.
Well, evaluating a string in (Common) Lisp just returns the string. Evaluating a symbol or list will actually do something interesting.