If you're interested, I spent some time figuring out how these attacks work and I blogged about it here: http://jsaxton.com/fun-with-wireshark-and-ie-java-exploits-p...
If you're interested, I spent some time figuring out how these attacks work and I blogged about it here: http://jsaxton.com/fun-with-wireshark-and-ie-java-exploits-p...
Except that the article is specifically about the Java plugin for browsers.
But, that said, the fact that there have been so many Java exploits reported compared to JavaScript exploits probably says a lot about the major browser developers (Mozilla, Google, Apple, Microsoft) compared to Oracle/Sun.
With Javascript there isn't actually a sandbox to break out of.
You mean like FileReader and WebGL/CL?
On Oracle's implementation. There are other JVMs to choose from.
Plus, can you guarantee that the JavaScript sandbox from all VMs are safe if hackers turn their attention to them?