ICQ 2001a Alpha and earlier allows remote attackers to automatically add arbitrary UINs to an ICQ user's contact list via a URL to a web page with a Content-Type of application/x-icq, which is processed by Internet Explorer.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2001-1286
http://www.securityfocus.com/bid/3226