Some older browsers are vulnerable to XSS attacks as such
Current versions of IE, FF, Chrome are
No. Image data is never executed as JavaScript. The if the src is a JavaScript link, the JavaScript is executed, but the fundamental reading of data that comes from a request to the src does not involve JavaScript.