There was a period a while back when a bunch of serious vulnerabilities were found. Heartbleed, Logjam, POODLE, FREAK, etc.
Nothing major like that has come up during the past year.
Question: If I setup a brand-new Linux VPS today with say Ubuntu 16.04 LTS -- with nginx webserver and Postfix/Dovecot mail server -- can I safely assume that I'm by default safe against all of those > 1 year old vulnerabilities?