Zone Labs IMsecure and IMsecure Pro before 1.5 allow remote attackers to bypass Active Link Filtering via an instant message containing a URL with hex encoded file extensions.
https://exchange.xforce.ibmcloud.com/vulnerabilities/18042
http://www.securityfocus.com/bid/11662
http://secunia.com/advisories/13169