These links point to vulnerabilities which have been patched, as would be expected by a program which is being actively supported. However it is interesting to note your contention that it is impossible for an exploit to occur on the client side if the core files are hosted on their servers. I did not know this.
Bookmarks