This causes a host of problems, and almost nobody is aware of them, or incorrectly assigns them to other causes. This results in a patchwork of "solutions" like virus scanners, signatures on executables, and a need for users to be exceedingly cautious about what they do with their computers. Because of this need for caution, users don't feel free to experiment with novel programs or web sites, lest their computer be infected with malware, etc.
Imagine your house without circuit breakers, or fuses. Imagine that there were no widespread use of them. The first shorted cord could potentially take down the power grid, and plunge millions into darkness. We can generally agree that circuit protection is a good idea.
When you run a program, you could explicitly specify the resources it is to have access to, instead of giving access to all of your files and folders. In fact, it doesn't even have to work differently in many cases, just replace the calls to file selection dialogs with equivalent calls to "power boxes" which return file access capabilities for the calling program. This allows the user to quickly and easily work in the manner to which they are accustomed, while simultaneously preventing malicious or just buggy code from accessing anything outside of the wishes of the user, no matter how evil the code is.
Spreading awareness of such systems, incorporating capability based security, is a worthy pursuit over the next decade.