When using the SNEWS protocol, Internet Explorer lacks its filtering engine and can trigger Outlook Express to be hit by a buffer overrun resulting in possible code execution.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/32536/IEmultiples.txt
Source: https://packetstormsecurity.com/files/32536/IEmultiples.txt.html