Sylpheed-Claws before 2.2.2 and Sylpheed before 2.2.6 allow remote attackers to bypass the URI check functionality and makes it easier to conduct phishing attacks via a URI that begins with a space character.
https://exchange.xforce.ibmcloud.com/vulnerabilities/27089
http://www.vupen.com/english/advisories/2006/2283
http://www.vupen.com/english/advisories/2006/2173
http://sylpheed.good-day.net/en/news.html%5C
http://sourceforge.net/project/shownotes.php?release_id=422662&group_id=25528