Buffer overruns are most common memory related RCE's. So bounds checking arrays/strings BY DEFAULT is needed.