programs where such bugs can be exploited in practice are very few and far between

Sure, if by "few and far between" you mean "only numerous documented instances every year for the past decade, and then some". Here's a small sample:

Those are just for font and image parsing, and only a handful of the code-execution parsing vulnerabilities published in those areas. Parser CX vulnerabilities are widespread and long-standing. Hell, we have CVE-2004-0200 from fifteen years ago.

In other words, you are very much wrong.

