Bugs are always bad (and security bugs even more so) - but I've always felt that Flash gets a disproportional amount of hate/hype in the media. To some degree it should be normal that the more widespread a technology is - the more it gets targeted for security exploits. If you run the popular browsers/plugins against the National Vulnerability Database, you'd get the following results (as of January 2014): - Internet…
So just counting high severity vulnerabilities, the chart is
IE: 314. IE with Flash: 483.
Chrome: 154: Chrome with Flash: 323.
Firefox: 86. Firefox with Flash: 255.
And of course, you can add a third column for Java and a fourth column for browser with Flash and Java.
I have no idea what their bugs-per-line-of-code are, perhaps they have the finest code on the planet. But from a surface area perspective, installing Flash makes you more vulnerable, period. And it really is not necessary, whereas it’s not like you can browse the web in pure Flash and not install a browser.