You're that confident in every single line of code you wrote?
This just smells so much like a Javascript script kiddy who wanted to join the cool brigade and write something h4kor1sh in C. Ugh.
I'm dying at the idea that someone would think C is the "cool brigade".
Let's not pretend that the people writing the unsafe code are unimaginably stupid. They are extremely imaginably stupid, as we all are.
Buffer overflows are simple inexcusable, especially if its "we didn't bother checking" rather than "we got the size wrong due to human error".
The first case is not normal, people like that should not be programming HTML let alone C code.