Mozilla Firefox 1.0.1 and possibly other versions, including Mozilla and Thunderbird, allows remote attackers to spoof the URL in the Status Bar via an A HREF tag that contains a TABLE tag that contains another A tag.
https://exchange.xforce.ibmcloud.com/vulnerabilities/19540
https://euvd.enisa.europa.eu/vulnerability/EUVD-2005-4802
http://www.vupen.com/english/advisories/2005/0260
http://www.securityfocus.com/bid/12798
http://securitytracker.com/id?1013423