You gain a little bit of security by blocking both. Java on the web is pretty much insignificant for consumers today, but you will lose a lot of functionality of modern web sites by turning off JavaScript Turning off the latter one is therefore not an option. Keep everything up to to date and you are usually safe.
Most of the malware doesn't rely on exploits of software bugs anyway, but on social engineering. Don't be tricked into installing something from an untrusted source. That's the most important thing to take care of.