HTML mail itself is a security problem. It has been used for fairly sophisticated phishing attacks in the past:
http://blog.mxlab.eu/2010/03/13/phishing-emails-with-attache...
It is almost certainly being used for phishing attacks now. It makes it difficult to give users visual cues about which emails can be trusted, since the sender could have embedded HTML in the message to present that same queue. An attacker might give the user the idea that a message was digitally signed by using HTML mail.
Security with HTML mail is a serious enough concern that the DoD will sometimes convert all incoming HTML mail to plaintext as a precaution:
http://it.slashdot.org/story/06/12/24/1922216/department-of-...
"It's not a violation of my privacy any more than the numerous pixels on any other website I read."
In other words, it is a violation of your privacy. The fact that it is a common practice on the web does not somehow make it less of a violation.