1. Ad blocking with ad server hostnames. http://pgl.yoyo.org/as/.
2. Direct and indirect eval. http://perfectionkills.com/global-eval-what-are-the-options/.
3. HTML5. http://www.w3.org/TR/html5/.
4. JavaScript Attack Vectors. https://code.google.com/p/google-caja/wiki/AttackVectors.
5. Lexer confusing attack. https://code.google.com/p/google-caja/wiki/JsControlFormatChars.