- Buffer overflow: somebody didn't sanitize the input (length of buffer).
- Stack smashing: somebody didn't sanitize the input (length of input).
- Format string vulnerability: somebody didn't sanitize the format string data.
- Integer converstion vulnerability: somebody didn't sanitize the integer input.
- SQL injection: somebody didn't sanitize the input before querying a database.
- Cross-site scripting: somebody didn't sanitize input and it got submitted and executed on behalf of the user.
- Remote file inclusion / Directory traversal: somebody didn't sanitize an input variable leading to a file path.
...and on, and on, and on. If people were as obsessed with input sanitization as they are with memory, I'll bet you a much larger percentage of attacks would be stopped. Too bad input sanitization isn't sexy.