CVE-2010-3765
Status: AnalyzedCritical (9.8)⚠ Active exploitation
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Base score: 9.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 83%
- Percentile among all scored CVEs: 100
- Score date: 9/30/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
CISA KEV — actively exploited
- Added to catalog: 10/6/2025
- Remediation due date: 10/27/2025
- Known ransomware use: Unknown
Affected technologies (3)
CWEs
- CWE-119
- CWE-119
References
- http://blog.mozilla.com/security/2010/10/26/critical-vulnerability-in-firefox-3-5-and-firefox-3-6/
- http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozilla_firefox
- http://isc.sans.edu/diary.html?storyid=9817
- http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050233.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050061.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050077.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050154.html
- http://norman.com/about_norman/press_center/news_archive/2010/129223/en?utm_source=twitterfeed&utm_medium=twitter
- http://secunia.com/advisories/41761
- http://secunia.com/advisories/41965
- http://secunia.com/advisories/41966
- http://secunia.com/advisories/41969
- http://secunia.com/advisories/41975
- http://secunia.com/advisories/42003
- http://secunia.com/advisories/42008
- http://secunia.com/advisories/42043
- http://secunia.com/advisories/42867
- http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.556706
- http://support.avaya.com/css/P8/documents/100114329
- http://support.avaya.com/css/P8/documents/100114335
- http://www.debian.org/security/2010/dsa-2124
- http://www.exploit-db.com/exploits/15341
- http://www.exploit-db.com/exploits/15342
- http://www.exploit-db.com/exploits/15352
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:213
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:219
- http://www.mozilla.org/security/announce/2010/mfsa2010-73.html
- http://www.norman.com/about_norman/press_center/news_archive/2010/129223/
- http://www.norman.com/security_center/virus_description_archive/129146/
- http://www.redhat.com/support/errata/RHSA-2010-0808.html
- http://www.redhat.com/support/errata/RHSA-2010-0809.html
- http://www.redhat.com/support/errata/RHSA-2010-0810.html
- http://www.redhat.com/support/errata/RHSA-2010-0861.html
- http://www.redhat.com/support/errata/RHSA-2010-0896.html
- http://www.securityfocus.com/bid/44425
- http://www.securitytracker.com/id?1024645
- http://www.securitytracker.com/id?1024650
- http://www.securitytracker.com/id?1024651
- http://www.ubuntu.com/usn/USN-1011-2
- http://www.ubuntu.com/usn/USN-1011-3
- http://www.ubuntu.com/usn/usn-1011-1
- http://www.vupen.com/english/advisories/2010/2837
- http://www.vupen.com/english/advisories/2010/2857
- http://www.vupen.com/english/advisories/2010/2864
- http://www.vupen.com/english/advisories/2010/2871
- http://www.vupen.com/english/advisories/2011/0061
- https://bugzilla.mozilla.org/show_bug.cgi?id=607222
- https://bugzilla.mozilla.org/show_bug.cgi?id=607222#c53
- https://bugzilla.redhat.com/show_bug.cgi?id=646997
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12108
- https://rhn.redhat.com/errata/RHSA-2010-0812.html
- http://blog.mozilla.com/security/2010/10/26/critical-vulnerability-in-firefox-3-5-and-firefox-3-6/
- http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozilla_firefox
- http://isc.sans.edu/diary.html?storyid=9817
- http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050233.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050061.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050077.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050154.html
- http://norman.com/about_norman/press_center/news_archive/2010/129223/en?utm_source=twitterfeed&utm_medium=twitter
- http://secunia.com/advisories/41761
- http://secunia.com/advisories/41965
- http://secunia.com/advisories/41966
- http://secunia.com/advisories/41969
- http://secunia.com/advisories/41975
- http://secunia.com/advisories/42003
- http://secunia.com/advisories/42008
- http://secunia.com/advisories/42043
- http://secunia.com/advisories/42867
- http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.556706
- http://support.avaya.com/css/P8/documents/100114329
- http://support.avaya.com/css/P8/documents/100114335
- http://www.debian.org/security/2010/dsa-2124
- http://www.exploit-db.com/exploits/15341
- http://www.exploit-db.com/exploits/15342
- http://www.exploit-db.com/exploits/15352
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:213
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:219
- http://www.mozilla.org/security/announce/2010/mfsa2010-73.html
- http://www.norman.com/about_norman/press_center/news_archive/2010/129223/
- http://www.norman.com/security_center/virus_description_archive/129146/
- http://www.redhat.com/support/errata/RHSA-2010-0808.html
- http://www.redhat.com/support/errata/RHSA-2010-0809.html
- http://www.redhat.com/support/errata/RHSA-2010-0810.html
- http://www.redhat.com/support/errata/RHSA-2010-0861.html
- http://www.redhat.com/support/errata/RHSA-2010-0896.html
- http://www.securityfocus.com/bid/44425
- http://www.securitytracker.com/id?1024645
- http://www.securitytracker.com/id?1024650
- http://www.securitytracker.com/id?1024651
- http://www.ubuntu.com/usn/USN-1011-2
- http://www.ubuntu.com/usn/USN-1011-3
- http://www.ubuntu.com/usn/usn-1011-1
- http://www.vupen.com/english/advisories/2010/2837
- http://www.vupen.com/english/advisories/2010/2857
- http://www.vupen.com/english/advisories/2010/2864
- http://www.vupen.com/english/advisories/2010/2871
- http://www.vupen.com/english/advisories/2011/0061
- https://bugzilla.mozilla.org/show_bug.cgi?id=607222
- https://bugzilla.mozilla.org/show_bug.cgi?id=607222#c53
- https://bugzilla.redhat.com/show_bug.cgi?id=646997
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12108
- https://rhn.redhat.com/errata/RHSA-2010-0812.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-3765
Raw JSON (NVD)
Show
{
"id": "CVE-2010-3765",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2010-3765",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "active"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-10-04T03:55:28.039016Z"
}
}
],
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2010-10-28T00:00:05.237",
"references": [
{
"url": "http://blog.mozilla.com/security/2010/10/26/critical-vulnerability-in-firefox-3-5-and-firefox-3-6/",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozilla_firefox",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://isc.sans.edu/diary.html?storyid=9817",
"tags": [
"Press/Media Coverage"
],
"source": "cve@mitre.org"
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050233.html",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050061.html",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050077.html",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050154.html",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://norman.com/about_norman/press_center/news_archive/2010/129223/en?utm_source=twitterfeed&utm_medium=twitter",
"tags": [
"Product"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/41761",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/41965",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/41966",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/41969",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/41975",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/42003",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/42008",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/42043",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/42867",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.556706",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://support.avaya.com/css/P8/documents/100114329",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://support.avaya.com/css/P8/documents/100114335",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.debian.org/security/2010/dsa-2124",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.exploit-db.com/exploits/15341",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.exploit-db.com/exploits/15342",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.exploit-db.com/exploits/15352",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:213",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:219",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.mozilla.org/security/announce/2010/mfsa2010-73.html",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.norman.com/about_norman/press_center/news_archive/2010/129223/",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.norman.com/security_center/virus_description_archive/129146/",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2010-0808.html",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2010-0809.html",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2010-0810.html",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2010-0861.html",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2010-0896.html",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/44425",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id?1024645",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id?1024650",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id?1024651",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.ubuntu.com/usn/USN-1011-2",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.ubuntu.com/usn/USN-1011-3",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.ubuntu.com/usn/usn-1011-1",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2010/2837",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2010/2857",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2010/2864",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2010/2871",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2011/0061",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=607222",
"tags": [
"Issue Tracking"
],
"source": "cve@mitre.org"
},
{
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=607222#c53",
"tags": [
"Issue Tracking"
],
"source": "cve@mitre.org"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=646997",
"tags": [
"Issue Tracking"
],
"source": "cve@mitre.org"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12108",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://rhn.redhat.com/errata/RHSA-2010-0812.html",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://blog.mozilla.com/security/2010/10/26/critical-vulnerability-in-firefox-3-5-and-firefox-3-6/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozilla_firefox",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://isc.sans.edu/diary.html?storyid=9817",
"tags": [
"Press/Media Coverage"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050233.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050061.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050077.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050154.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://norman.com/about_norman/press_center/news_archive/2010/129223/en?utm_source=twitterfeed&utm_medium=twitter",
"tags": [
"Product"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/41761",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/41965",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/41966",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/41969",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/41975",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/42003",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/42008",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/42043",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/42867",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.556706",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://support.avaya.com/css/P8/documents/100114329",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://support.avaya.com/css/P8/documents/100114335",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.debian.org/security/2010/dsa-2124",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.exploit-db.com/exploits/15341",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.exploit-db.com/exploits/15342",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.exploit-db.com/exploits/15352",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:213",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:219",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.mozilla.org/security/announce/2010/mfsa2010-73.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.norman.com/about_norman/press_center/news_archive/2010/129223/",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.norman.com/security_center/virus_description_archive/129146/",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2010-0808.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2010-0809.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2010-0810.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2010-0861.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2010-0896.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/44425",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1024645",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1024650",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1024651",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ubuntu.com/usn/USN-1011-2",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ubuntu.com/usn/USN-1011-3",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ubuntu.com/usn/usn-1011-1",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2010/2837",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2010/2857",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2010/2864",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2010/2871",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2011/0061",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=607222",
"tags": [
"Issue Tracking"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=607222#c53",
"tags": [
"Issue Tracking"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=646997",
"tags": [
"Issue Tracking"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12108",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://rhn.redhat.com/errata/RHSA-2010-0812.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-3765",
"tags": [
"US Government Resource"
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware."
},
{
"lang": "es",
"value": "Firefox versiones 3.5.x hasta 3.5.14 y versiones 3.6.x hasta 3.6.11, Thunderbird versiones 3.1.6 anteriores a 3.1.6 y versiones 3.0.x anteriores a 3.0.10, y SeaMonkey versiones 2.x anteriores a 2.0.10, de Mozilla, cuando JavaScript está habilitado, permite a los atacantes remotos ejecutar código arbitrario por medio de vectores relacionados con nsCSSFrameConstructor::ContentAppended, el método appendChild, el seguimiento incorrecto de índices y la creación de varias tramas, lo que desencadena corrupción de memoria, como se explotó “in the wild” en octubre de 2010 por el malware Belmoo."
}
],
"lastModified": "2026-06-16T23:23:28.500",
"cisaActionDue": "2025-10-27",
"cisaExploitAdd": "2025-10-06",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mozilla:firefox:3.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "76CD3BDF-A079-4EF3-ABDE-43CBDD08DB1F"
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:3.5.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "031E8624-5161-43AF-AF19-6BAB5A94FDD8"
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:3.5.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "54186D4A-C6F0-44AD-94FB-73B4346ABB6B"
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:3.5.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "47E50AD9-BA35-4817-BD4D-5D678FC5A3C5"
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:3.5.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DD09DE40-8C9B-41EA-B372-9E4E4830E8F4"
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:3.5.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F223FB83-0EDB-4429-94B9-1AEEF314B73F"
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:3.5.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BC6B977F-292F-4981-95A0-6065A3C487D5"
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:3.5.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "342226B9-2C0C-416C-81FE-19C49F03AA88"
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:3.5.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2A6A28E0-F67A-4275-B0D9-A02822E9EF7E"
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:3.5.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ECAB4696-76F3-458C-B33B-D7F8690C60A0"
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:3.5.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BBB444FD-15F3-4447-9EA8-1669779A5749"
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:3.5.11:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F92E2EF3-A612-476F-9D31-1EEC240C7EA7"
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:3.5.12:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0F175D30-2416-4172-BF11-DA78D252D608"
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:3.5.13:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5DD3F168-3EF4-492E-BBAA-EACB1357C709"
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:3.5.14:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4B46BA97-2860-45E4-9FD3-F418A202E4F0"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mozilla:firefox:3.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F3782354-7EB7-49D2-B240-1871F6CB84C7"
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:3.6.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "30D47263-03AD-4060-91E3-90F997B3D174"
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:3.6.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AFD775DF-277E-4D5B-B980-B8E6E782467D"
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:3.6.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C8587BFD-417D-42BE-A5F8-22FDC68FA9E6"
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:3.6.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D7364FAB-EEE9-4064-A8AD-6547239F9AB3"
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:3.6.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4C50485F-BC7B-4B70-A47B-1712E2DBAC5A"
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:3.6.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "51EE386B-0833-484E-A2AB-86B4470D4D45"
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:3.6.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C3EF1B4D-6556-4B3C-BDD0-6348A4D4A91D"
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:3.6.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "68C5C7CF-005B-42FC-B950-90303F0CC115"
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:3.6.11:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0B2FA2CF-7FE4-43B1-96A0-C14666EDBD7B"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:3.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4BF605F6-2A84-4DE5-AB62-282E9C46479B"
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:3.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "08F10B5E-0780-4756-919C-B0C00C673412"
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:3.0.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6D930F0F-DCC3-4905-A4B1-288F0CCC6975"
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:3.0.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CBA0F9D4-B68A-4018-BC4E-95B87A1A8489"
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:3.0.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "61CCB291-B71B-40D3-8493-215003851BDB"
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:3.0.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AFD1FE7A-B888-461D-93F3-B71C94B4AA56"
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:3.0.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E2727C9C-618D-4AEF-B7BE-8BE5935483F7"
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:3.0.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "95B21CE4-AF78-4D1B-A73E-84E83DB4A2C4"
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:3.0.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "48F3528F-4E43-4D91-957E-49C7DB2A135A"
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:3.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "27B9EA91-A461-42CE-9ED7-3805BD13A4B6"
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:3.1.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8C48E432-8945-4918-B2A4-AD2E05A51633"
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:3.1.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2A95B301-A72B-4F95-A7D6-4B574E9D3BDA"
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:3.1.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "968C261F-A7D5-4EB6-BCFF-EE40DB5A11D9"
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:3.1.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EB49CD91-C21E-4494-97CF-DDCFB38B2D92"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mozilla:seamonkey:2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "58EB8E8A-84DE-43AA-B8F0-B585FB73D724"
},
{
"criteria": "cpe:2.3:a:mozilla:seamonkey:2.0:alpha_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C19C0BF7-390D-4E2E-BA32-28DFF73C55F6"
},
{
"criteria": "cpe:2.3:a:mozilla:seamonkey:2.0:alpha_2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5FE5E50C-80ED-4CA7-BC85-8BD2E324D527"
},
{
"criteria": "cpe:2.3:a:mozilla:seamonkey:2.0:alpha_3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FEBF912C-A12E-4DBD-84AC-8B440E190BCE"
},
{
"criteria": "cpe:2.3:a:mozilla:seamonkey:2.0:beta_1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9B8EDED6-29EF-4A9F-955D-F5E6611C2141"
},
{
"criteria": "cpe:2.3:a:mozilla:seamonkey:2.0:beta_2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EDC9C82D-586A-48F4-B540-1E2AE79806B3"
},
{
"criteria": "cpe:2.3:a:mozilla:seamonkey:2.0:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "51FCF83B-630A-4413-BFAA-0C24A6B8F4F4"
},
{
"criteria": "cpe:2.3:a:mozilla:seamonkey:2.0:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "84B2AA0A-0220-49DD-82CD-37FDC563F146"
},
{
"criteria": "cpe:2.3:a:mozilla:seamonkey:2.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D754AF10-1E43-46C8-A444-E7DB3401509D"
},
{
"criteria": "cpe:2.3:a:mozilla:seamonkey:2.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "34182167-F1DF-455B-BFDB-0A8491590479"
},
{
"criteria": "cpe:2.3:a:mozilla:seamonkey:2.0.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B8ECA6CE-20D0-4A4F-B376-888A9328B044"
},
{
"criteria": "cpe:2.3:a:mozilla:seamonkey:2.0.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1FEFCAB0-E57A-46E8-94C7-8510BB87C6B2"
},
{
"criteria": "cpe:2.3:a:mozilla:seamonkey:2.0.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9FB5C972-AF7B-4EC7-BCE5-867CACCF5C19"
},
{
"criteria": "cpe:2.3:a:mozilla:seamonkey:2.0.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C68DBB31-7804-446E-9A53-073E4B74E851"
},
{
"criteria": "cpe:2.3:a:mozilla:seamonkey:2.0.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "31ADCC51-CE05-4EB6-BE8F-B64FD62946A1"
},
{
"criteria": "cpe:2.3:a:mozilla:seamonkey:2.0.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "387390AE-CF25-47ED-BD36-F42455DE1A4B"
},
{
"criteria": "cpe:2.3:a:mozilla:seamonkey:2.0.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "78D5F0AD-9974-40A1-942F-0F03A278DAD9"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org",
"cisaRequiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"cisaVulnerabilityName": "Mozilla Multiple Products Remote Code Execution Vulnerability"
}