Many browser exploits that break out of the sandbox take advantage of javascript. Disabling it prevents entire classes of exploits. Also, a lot of ad networks use javascript as a tracking tool.
specifically, are there javascript-only (or js+css+html only) exploits in recent chrome or firefox ?