But those would be logic errors, not memory management errors. If someone is stupid enough to pass user input directly to a shell or database then yes, they will get compromised.
But these comprise only 30% of all security errors as the research shows. Most are due to memory management issues.