If you defined a landing page which would provide you with the search results, you could easily browse through the result set using an offset.
This offset might be an integer, a string or whatever. I´m seeing a security issue here.
This offset, called "AS_offset", used as a negative integer makes modX react with a Parse Error as seen here:
http://www.modxcms.com/search-results.html&FSF_offset=-70&FSF_search=modx
You could also make Apache (or what ever you are using) using high CPU-load using a string as an offset, seen here:
http://www.modxcms.com/search-results.html&FSF_offset=bla&FSF_search=modx
This issue might be solved very easily by checking the $_GET-Variable of AS_offset.
You can find this code near line 300 in "ajaxSearch.class.inc.php".
I fixed it on my own like this (might be a bit naive, but works

):
//check for paging offset
$offset_val = 0;
if(isset($_GET['AS_offset']))
{
$offset_val = intval($_GET['AS_offset']);
}
if($offset_val >= 0)
$this->offset = $offset_val;
Edit:
If the offset exceeds the number of documents retrieved, modx crashes too... this needs to be fixed.
Greetings from Germany