"Not enough eyes"? OpenSSL is among the most aggressively reviewed codebases in the industry. Everyone reads OpenSSL. The problem with OpenSSL isn't that it didn't get "enough eyes". The problem is that the code is bad. It's disorganized, serves too many interests, and (particularly in the TLS portion of the tree) is a grab bag of functionality.
OpenSSL implements twenty two TLS extensions. NSS, the library used by Firefox and Chrome, implements 11. Why was it possible for some dude in Germany to specify a TLS extension that nobody really needed and then implement it in OpenSSL as the client default? Because OpenSSL is a bazaar, not a cathedral, and nobody really claims ownership of what the code in openssl-1.0.1e/ssl is supposed to do.
Also: check your availability bias. "Burned down the Internet"? This was a bad bug, but it wasn't unique; nginx had the same bug just a couple years ago (I know this because we found it). But shove all that aside, because these are all codebases that have hosted remote code execution flaws.