peter bassill · operator
$ cve CVE-2010-3765 JSON

CVE-2010-3765 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 83.2% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2025-10-27.

Description

Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS83.16% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-119
On CISA KEVyes — remediate by 2025-10-27
Public exploityes
Published2010-10-28
Last modified2026-06-16

CISA KEV

NameMozilla Multiple Products Remote Code Execution Vulnerability
Added2025-10-06
Due2025-10-27
Vendor / productMozilla / Multiple Products
Ransomware usenone reported

Affected (3)

VendorProduct
mozillafirefox
mozillaseamonkey
mozillathunderbird

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD