2002 and 2007, according to Wikipedia. I'm skeptical about OpenBSD being more secure overall, in the real world (who has time to apply patches manually?!) But, to be fair, I'm pretty sure Debian and Ubuntu had a big OpenSSL-related fiasco just recently.
There have been lots of security bugs. But no "remote holes in the default install", which is OpenBSD's marketing slogan. That's the point that I was making. It's a dumb metric.