Do you remember the license agreement you clicked through for Java? (By the way, even for a paid-for software, I guess a similar answer would be applicable.)
The "culprit" will be the one who tries to exploit (maybe even the one who finds/talks about it), not the one that leaves everything exploitable.
For me, this situation is not satisfying; however, Very Serious People usually think it is.