Когда-то
licvidator уверял меня в том, что java безопаснее чем, скажем, ядро linux из-за sandbox.
А вот
тут говорят: "
Sun Java, PHP, and Apache continue to be among the Top 10 vendors having the most severe vulnerabilities for the first half of 2009".
И еще, пара уязвимостей, касающихся Java из списка самых опасных:
3. Sun Java System Access Manager Cross-Domain Controller (CDC) Cross
Site Scripting Vulnerability
Sun Java System Access Manager is prone to a cross-site scripting vulnerability
because it fails to sufficiently sanitize user-supplied data.
5. Sun Java System Web Server Reverse Proxy Plug-in Cross-Site Scripting
Vulnerability
Sun Java System Web Server is prone to a cross-site scripting vulnerability
because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the
browser of an unsuspecting user in the context of a site that uses the affected
functionality. This may help the attacker steal cookie-based authentication
credentials and launch other attacks.