It's not only "security holes" that are released
It's sometimes incomplete data validation and associated error trapping.
Some years ago I was asked to debug a crashed program. The crash was caused by the string NOPHONE in a telephone number field. The original programmer had assumed a phone number would always be numeric.