trying to understand what you just said: do you mean they may have buffer-overrun vulnerabilities, just as they are new projects? a lot of nosql projects are written in erlang and java btw.
I don't like the term "buffer overflow" because things haven't been that simple since the '90s (the recent Aurora kerfluffle happened because IE freed memory in the wrong order, no overrun involved). But yes, the point is you're trading a problem in a domain where we know how to mitigate problems for a maybe less likely problem in a domain where we have no idea how to mitigate problems.
Is there any reason why sql databases should be less vulnerable to that other type of problems?
Yes: because they've been tested extensively for over a decade for them, especially over the attack vectors exposed on web applications.