CVE-2007-2227
The MHTML protocol handler in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handle Content-Disposition "notifications," which allows remote attackers to obtain sensitive information from other Internet Explorer domains, aka "Content Disposition Parsing Cross Domain Information Disclosure Vulnerability."
Date published : 2007-06-12
http://www.securityfocus.com/bid/24410
http://www.securityfocus.com/archive/1/472002/100/0/threaded