> Servers are directly attackable over the internet, unlike browsers :) Browsers are a very well hardened target at this point after decades of attacks.
OTOH, browsers are expected to have an ever-expanding array of capabilities on behalf of the end user, which leads to ever-increasing code complexity and size. Moreover, breaking into any individual browser instances nets you almost nothing, so the interesting security issues are the ones that apply across the board (allowing you to do really large-scale blackhat stuff).
Servers, on the other hand, can be relatively static targets in terms of functionality and code, can use modular code design in a way that is harder for browsers to pull off, and have been much more hardened than browsers over time for the simple reason that even a single server break in has way more implications than a single browser break in.
I don't know how much money I'd put on this wager, but I'd bet that getting into a random nginx install is much, much harder than getting into a random browser instance.