...because a victim would have to go to an attacker-owned Web page to be attacked. The Internet Explorer vulnerabilitiesinvolve the fact that the software doesn't check the type of an object returned from a Web server and because a flaw...
http://news.zdnet.com/2100-1009_22-5066511.html