Tip: go into Tools > Options, click on Viewing Mail, and un-check "allow executables in HTML content." For even more safety, un-check "Use Microsoft Viewer."
Now you're not using IE as a message viewer so you're safe from scripts, ActiveX controls, and the million other exploits IE allows. The downside is some fancier HTML emails will be messed up, but when you need to see one shown properly:
* double click on the message subject to switch from preview pane to full view
* right-click and choose "send to browser"