Security? The browser sandboxes everything.
Also, browsers aren't bug-free, and enabling Javascript significantly increases the attack surface.
http://en.wikipedia.org/wiki/Online_banking
http://en.wikipedia.org/wiki/Cross-site_scripting