Javascript vulnerabilities . Denial of Service . Infinite loops in scripts . Memory consumption . http://www.devarticles.com/c/a/JavaScript/JavaScript-Security/6/ . Cross site scripting . Attack on DNS pinning . Attack on browser cache . CSS browser history attack . Danger of including external scripts § External scripts are executed within the same-origin context of the page that includes them . Cross-Site Request Forgery . Response Splitting . http://taossa.com/index.php/2007/02/08/same-origin-policy/