I think the issue is most software is not designed with security as a primary concern, so a determined users can produce a convoluted input that breaks a system. Having said that, if you take out buffer overflow exploits, how many games would still be hacked?