iframes
inline css style tags with an @import option.
external css style tags
object embed tags
It also honours meta refresh tags and opens the standard web browser entire automatically just by viewing the email.
Can you please test Froyo using my app at https://secure.grepular.com/email_privacy_tester/
I'd be interested to know if all of these flaws still exist in newer versions of Android...