Eudora 6.1.0.6 allows remote attackers to obfuscate URLs displayed in the status bar by inserting a large number of characters (e.g. spaces coded as " ") in the middle of the URL.
https://exchange.xforce.ibmcloud.com/vulnerabilities/16105
http://www.eudora.com/download/eudora/windows/6.1.2/RelNotes.txt