http://www.metasploit.com/modules/exploit/windows/browser/ie... was a cool one, but really, almost EVERY vulnerability requires JavaScript for the heap spray, even if the bug is somewhere else. Of course, running plug-ins in web pages is even more retarded than running JavaScript. By the way, images can spray the heap too, but, for some reason, they are not commonly used.