This seemed like an interesting question, so I did a little test tonight: I booted my desktop with my newest Knoppix CD. Used all defaults (no cheat codes, default kernel). When Knoppix came up I made sure I was on the network (clicked the links to the websites on the default browser) and then shut down the browser.

I then put another live CD in my notebook and booted that. Ran nmap against my desktop's IP address. With a bunch of scanning this is all I could find:

Open port 68, dhcp client.
Open Port 6000, X11

No other ports were open, and I scanned all 64k, not just the low defaults.

It doesn't seem like there's a lot of vulnerability from the port 68 issue (might help someone on the local lan confuse your system, but ettercap will allow local hacks even without port 6.

Not sure what the port 6000 issues are. Anyone?

My thought remains the same as before the test - assuming you have a high speed connection, use a hardware Home DSL/cable router. Forward only the ports needed to the Knoppix computer (in this case certainly don't forward port 6000 unless you know why). You'll have taken reasonable precautions and be reasonably safe (nothing being completely safe).