No, old programmers would do much worse. And the threat model for those systems didn't take in the web as an attack surface. The bugs described would only help with local privilege escalation before. Now they can be used to get access to the networked application.
E.g. the browser uses a vulnerable library call with input from a web page, and that library call alters the return stack according to the input. The browser is now compromised.