Microsoft Windows Live Messenger 8.0 and earlier, when gestual emoticons are enabled, allows remote attackers to cause a denial of service (CPU consumption) via a long string composed of ":D" sequences, which are interpreted as emoticons.
http://www.securityfocus.com/archive/1/452645/100/0/threaded
http://www.securityfocus.com/archive/1/452620/100/0/threaded