Does anyone know of anything (theoretical or otherwise) that could exploit some kind of instant messenger to compromise network security?

In my research I have found several problems relating to recieving files, but are there any kind of vulnerabilities that do not require file trnasfer?

Thanks for any info/resources you may offer.

--
nickel