Yahoo! Messenger versions 8.1.0.29 and below suffer from a javascript injection flaw.
4b364470e048ac46853af776177c87a93533e952fea81b7179eb21d20ccdf21b
It is possible to spoof the address bar in IE by using Shockwave Flash.
6ef049622aecfb0367b58dc276dcb4ff4372dc8fae9f6d0f3fdd15c90fbbe1c9
An Internet Explorer Address Bar Spoofing Vulnerability that allows an attacker to inject a malicious shockwave-flash application into Internet Explorer while displaying another URL in the address bar.
3c79f849ce1fcbf0732dd771f03cec631b61c3c30910c252789e5b0e752fe2a8