Lately, yes. Over the last couple of years (Read: after Microsoft mostly cleaned up its act), Java has been been one of the primary sources of client exploits, along with Adobe products.
I don't know that there's anything special wrong with it other than that anything deployed widely enough makes a good target.
Comments
Lately, yes. Over the last couple of years (Read: after Microsoft mostly cleaned up its act), Java has been been one of the primary sources of client exploits, along with Adobe products.
I don't know that there's anything special wrong with it other than that anything deployed widely enough makes a good target.
Edit: here's one sample article from last year:
http://isc.sans.edu/diary.html?storyid=9916