Is this typically through Java Applets/other plugins?
Is this typically through Java Applets/other plugins?
Because browsers are written in very unsafe programming languages (C++), bugs are regularly exploitable so that by specially crafting the bug-triggering input data they can be fooled to scribble content-controlled data inside the browser's memory space. For example, a memory handling bug might let the page overwrite some of the browser's code with data coming from the web page.
This lets the web page break into your computer, running arbitrary code of its choosing on your box.
Browser plugins can be similarly targeted instead of the browser itself.
My point was that it's not a C specific problem, though. Most browsers are in fact built on C, I agree. This is due primarily to the speed and performance of the language that is harder to reach with other languages.
It is definitely a more difficult language to write, as it is much more "raw," but that doesn't make it inherently unsafe to use, or any more unsafe than other languages.
If you vote because you think C is unsafe, carry on. You're wrong, though.
And it's not a "potentially" thing, as is apparent to anyone following news about browser vulnerabilities. For a recent public performance, see pwn2own - http://nakedsecurity.sophos.com/2014/03/14/pwn2own-day-two-c...
specially crafted jpgs and gifs have also been used to exploit overflows in image handling code.
There are in number of ways for nasty things to happen just by visiting a page.