Mozilla Firefox 1.0.1 and possibly other versions, including Mozilla and Thunderbird, allows remote attackers to spoof the URL in the Status Bar via an A HREF tag that contains a TABLE tag that contains another A tag.
https://exchange.xforce.ibmcloud.com/vulnerabilities/19540
http://www.vupen.com/english/advisories/2005/0260
http://securitytracker.com/id?1013423