"Microsoft's Internet Explorer 7 offers significant security improvements over its deservedly criticized predecessor.
But the new IE still does not do enough to protect users.
....malicious scripting attacks remain a big problem. Some miscreant Web sites use scripting code (such as JavaScript) to exploit security holes. This can allow them to perform drive-by installations of spyware or Trojan horse programs. IE 7 has a host of features designed to thwart exploits, including showing a pop-up warning that lets the user know when a site is trying to use scripting. But the new features don't go far enough.
Firefox NoScript plug-in (a free download at NoScript.net) provides an elegant solution to the problem of malicious scripting. Once installed, NoScript prevents scripting from working at any Web site you visit until you approve it for that particular site. Being able to control scripting on a site-by-site basis with a single mouse click gives you a powerful security advantage."
Article: PC World