CVE-2010-3765 KEV EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 83.2% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2025-10-27.
Description
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 83.16% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | yes — remediate by 2025-10-27 |
| Public exploit | yes |
| Published | 2010-10-28 |
| Last modified | 2026-06-16 |
CISA KEV
| Name | Mozilla Multiple Products Remote Code Execution Vulnerability |
|---|---|
| Added | 2025-10-06 |
| Due | 2025-10-27 |
| Vendor / product | Mozilla / Multiple Products |
| Ransomware use | none reported |
Affected (3)
| Vendor | Product |
|---|---|
| mozilla | firefox |
| mozilla | seamonkey |
| mozilla | thunderbird |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Mozilla Firefox - Interleaving 'document.write' / 'appendChild' (Metasploit) | 2011-02-22 |
| exploit-db | Mozilla Firefox 3.6.8 < 3.6.11 - Interleaving 'document.write' / 'appendChild' Remote Overflow | 2010-10-29 |
| exploit-db | Mozilla Firefox - Interleaving 'document.write' / 'appendChild' Denial of Service | 2010-10-28 |
| exploit-db | Mozilla Firefox - Simplified Memory Corruption (PoC) | 2010-10-28 |
References
- http://blog.mozilla.com/security/2010/10/26/critical-vulnerability-in-firefox-3-5-and-firefox-3-6/
- http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozilla_firefox
- http://isc.sans.edu/diary.html?storyid=9817
- http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050233.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050061.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050077.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050154.html
- http://norman.com/about_norman/press_center/news_archive/2010/129223/en?utm_source=twitterfeed&utm_medium=twitter
- http://secunia.com/advisories/41761
- http://secunia.com/advisories/41965
- http://secunia.com/advisories/41966
- http://secunia.com/advisories/41969
- http://secunia.com/advisories/41975
- http://secunia.com/advisories/42003
- http://secunia.com/advisories/42008
- http://secunia.com/advisories/42043
- http://secunia.com/advisories/42867
- http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.556706
- http://support.avaya.com/css/P8/documents/100114329
- http://support.avaya.com/css/P8/documents/100114335
→ the Explorer · watch your stack · NVD