As near as I can tell, Thomas Lopatic kicked off the era of modern memory corruption exploits in February 1995 with his HPUX NCSA httpd overflow. That was followed shortly by 8lgm's Sendmail 8.6.12 syslog() stack overflow, which 8lgm created a small mania about by explaining roughly how the bug worked but not publishing the exploit, which meant every amateur vulnerability researcher at the time (myself included) spent a couple weeks figuring it out for ourselves.
1988 to 1995 is a long time! During that period, near as I can tell, nobody published or even referenced a modern memory corruption flaw ("modern" meaning "allowed you to upload code into a remote system"; there were overflows prior to 1995, but they worked by overwriting variables in memory to alter program logic). Why did Morris have this technique back in 1988? (Besides the obvious reason). Why did nobody extend the work between '88 and '95? The whole Internet was vulnerable to this bug! And that timeframe was the hacker renaissance; it corresponds to the Sun Devil raids and the LoD/MoD war.