Embedded HTML and Javascript code that executes as the email is "run" (read, displayed). However, this should be less of an issue I would think because by default, this type of stuff should be disabled.