well I've read the paper a multiple times, most of these "exploits" need "malicious code", how is that even possible? If somebody can inject malicious code I would say that the game is already over.
Of course Applets are different, but I always hoped that they will be removed soon and that will be the case (soon).