CVE-2010-3765
Mozilla Multiple Products Remote Code Execution Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 27 October 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 83.28% probability · 100th percentile
- CISA KEV
- Listed 6 October 2025 · due 27 October 2025
- Weakness
- CWE-119
- Affected
- mozilla/firefox · mozilla/thunderbird · mozilla/seamonkey
- Source
- cve@mitre.org
CISA notes
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://www.mozilla.org/en-US/security/advisories/mfsa2010-73 ; https://nvd.nist.gov/vuln/detail/CVE-2010-3765
References
- http://blog.mozilla.com/security/2010/10/26/critical-vulnerability-in-firefox-3-5-and-firefox-3-6/Vendor Advisory
- http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozilla_firefoxBroken Link
- http://isc.sans.edu/diary.html?storyid=9817Press/Media Coverage
- http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050233.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050061.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050077.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050154.htmlThird Party Advisory
- http://norman.com/about_norman/press_center/news_archive/2010/129223/en?utm_source=twitterfeed&utm_medium=twitterProduct
- http://secunia.com/advisories/41761Vendor Advisory
- http://secunia.com/advisories/41965Vendor Advisory
- http://secunia.com/advisories/41966Vendor Advisory
- http://secunia.com/advisories/41969Vendor Advisory
- http://secunia.com/advisories/41975Vendor Advisory
- http://secunia.com/advisories/42003Vendor Advisory
- http://secunia.com/advisories/42008Vendor Advisory
- http://secunia.com/advisories/42043Vendor Advisory
- http://secunia.com/advisories/42867Vendor Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.556706Third Party Advisory
- http://support.avaya.com/css/P8/documents/100114329Third Party Advisory
- http://support.avaya.com/css/P8/documents/100114335Third Party Advisory
- http://www.debian.org/security/2010/dsa-2124Third Party Advisory
- http://www.exploit-db.com/exploits/15341Exploit
- http://www.exploit-db.com/exploits/15342Exploit
- http://www.exploit-db.com/exploits/15352Exploit
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:213Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:219Third Party Advisory
- http://www.mozilla.org/security/announce/2010/mfsa2010-73.htmlThird Party Advisory
- http://www.norman.com/about_norman/press_center/news_archive/2010/129223/Broken Link
- http://www.norman.com/security_center/virus_description_archive/129146/Broken Link
- http://www.redhat.com/support/errata/RHSA-2010-0808.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.