Wow. I'm ever so stunned that, even adding app problems in, Win XP is less vulnerable than Linux.
Cobblers. IE vulnerabilities alone outnumber a conservative (not world + dog packages) Linux distro.
Read bugtraq and NTBugtraq. There's not a week goes by without some discussion regarding exploiting IE, and/or a new vulnerability announced. And I think "street cred" is lacking somewhat in finding IE vulns, it's like pointing out that there's holes in swiss cheese :-)