I may be missing something, but I have been running XP onVBox for a long while without problems. no AV or FW, but when I tried a "shields up"test it showed no ports at all visible to an outside probe. I took this to be an indication of a reasonable security level.
I agree that sloppy use of the browser could drop me right in it, but surely otherwise this sounds pretty safe?
J