Let us not forget that Adobe's PDF reader actually has a good track record against alternative implementations, such as the one used by Apple. Given Flash's ubiquity (which makes it a prime target for production exploits) it is actually doing quite well at the whole security game.
“Later this month at the CanSecWest security conference in Vancouver, Charlie Miller plans to unveil research that he says has turned up 30 previously unknown critical security vulnerabilities in common software, 20 of which are in Apple’s Preview application,” Andy Greenberg reports for Forbes. “In other words, he says he’s found 20 different ways that a cybercriminal could hijack the machine of any Mac user tricked into opening an infected PDF–or given that Safari uses the same code as Preview to render PDFs, simply visiting an infected Web page.”
...
“After running his fuzzer program on the applications for 3 weeks each, Miller found nearly a thousand unique ways to make the programs crash, and combed through those data to find which of those bugs allowed him to take control of the program,” Greenberg reports. “The results don’t look good for Apple: 20 exploitable bugs in Preview compared with either 3 or 4 each in Reader, PowerPoint, and OpenOffice… Even so, Miller doesn’t confine his criticism to Apple. ‘Microsoft, Apple, and Adobe all have huge security teams, and I’m one guy working out of my house,’ he says. ‘I shouldn’t be able to find bugs like these, ever.’”
“Later this month at the CanSecWest security conference in Vancouver, Charlie Miller plans to unveil research that he says has turned up 30 previously unknown critical security vulnerabilities in common software, 20 of which are in Apple’s Preview application,” Andy Greenberg reports for Forbes. “In other words, he says he’s found 20 different ways that a cybercriminal could hijack the machine of any Mac user tricked into opening an infected PDF–or given that Safari uses the same code as Preview to render PDFs, simply visiting an infected Web page.”
...
“After running his fuzzer program on the applications for 3 weeks each, Miller found nearly a thousand unique ways to make the programs crash, and combed through those data to find which of those bugs allowed him to take control of the program,” Greenberg reports. “The results don’t look good for Apple: 20 exploitable bugs in Preview compared with either 3 or 4 each in Reader, PowerPoint, and OpenOffice… Even so, Miller doesn’t confine his criticism to Apple. ‘Microsoft, Apple, and Adobe all have huge security teams, and I’m one guy working out of my house,’ he says. ‘I shouldn’t be able to find bugs like these, ever.’”
[ http://macdailynews.com/2010/03/22/dumb_fuzzer_to_discuss_20... ]