Stack-based buffer overflow in Ipswitch IMail Express Web Messaging before 8.05 might allow remote attackers to execute arbitrary code via an HTML message with long "tag text."
https://exchange.xforce.ibmcloud.com/vulnerabilities/15841
http://www.securityfocus.com/bid/10106