Earlier quoted context omitted.
I would argue that a world that didn't have JS would make these types of attacks more common, not less common. Because in that world, people would have to download desktop apps for everything, which would make people used to downloading desktop apps from random Web pages, which would make malware easier to distribute. In fact, we don't have to imagine that world: it was the world of the late 90s.
In an ideal world, native apps shouldn't be able to compromise your whole system.
Hell, we even tried applets!