IE has made some good changes in recent past and vulnerability of getting hit by spyware is a bit below than what it used to be...
Firefox, although built on top of IE API, showed immense resistence and security layers agains spywares from its arrival.... The cons for firefox is really to set it up so things like Jscript and DHTML are actually run on the browser.... IE has those things set to go by default... but then, spywares are mostly spread by scripts run on the client's side hence, the justification why firefox has been good in sheilding the boxes from these threats...
If things are set up properly, they both are fine.... Firefox actually have some cool add-ons to it which IE lacks, so if you are into those catchy Add-ons, you might wanna abandon IE