Qualcomm Eudora 5.1 allows remote attackers to execute arbitrary code via an HTML e-mail message that uses a file:// URL in a t:video tag to reference an attached Windows Media Player file containing JavaScript code, which is launched and executed in the My Computer zone by Internet Explorer.
https://exchange.xforce.ibmcloud.com/vulnerabilities/8609
http://www.securityfocus.com/bid/4343