Mikhail Kozlov, a Microsoft employee,
suggests visually comparing the number of identified and fixed vulnerabilities in Oracle 8, 9 and 10 against Microsoft SQL Server 7, 2000 and 2005 from 2001 to 2006.
Above - vulnerabilities in Oracle, below - in SQL Server. Charts are taken from the NGSSoftware Insight Security Research report (
PDF ).

