I'd split that first list into two:
1a. Arbitrary apps can listen on ports without permissions.
1b. Arbitrary apps can access local ports without permissions.
I've recently been experimenting with running the browser (on my desktop) in a network namespace precisely because of these reasons. Random websites shouldn't be able to access services running on localhost.