In webkit/Source/WebCore/html/HTMLMediaElement.cpp, the method HTMLMediaElement::getStartDate doesn't check if m_player is null: double HTMLMediaElement::getStartDate() const { return m_player->getStartDate().toDouble(); } So this simple one line javascript can crash the browser: document.createElement('video').getStartDate()
*** This bug has been marked as a duplicate of bug 16898 ***