CVE-2010-3765
Summary
| CVE | CVE-2010-3765 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-10-28 00:00:05 UTC |
| Updated | 2026-04-22 14:15:57 UTC |
| Description | Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware. |
Risk And Classification
Primary CVSS: v3.1 9.8 CRITICAL from ADP
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.832790000 probability, percentile 0.996480000 (date 2026-07-21)
CISA KEV: Listed on 2025-10-06; due 2025-10-27; ransomware use Unknown
Problem Types: CWE-119 | n/a | CWE-119 CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ADP | DECLARED | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 9.3 | AV:N/AC:M/Au:N/C:C/I:C/A:C |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
CISA Known Exploited Vulnerability
| Vendor | Mozilla |
|---|---|
| Product | Multiple Products |
| Name | Mozilla Multiple Products Remote Code Execution Vulnerability |
| Required Action | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
| Notes | https://www.mozilla.org/en-US/security/advisories/mfsa2010-73 ; https://nvd.nist.gov/vuln/detail/CVE-2010-3765 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Firefox | 3.5 | All | All | All |
| Application | Mozilla | Firefox | 3.5.1 | All | All | All |
| Application | Mozilla | Firefox | 3.5.10 | All | All | All |
| Application | Mozilla | Firefox | 3.5.11 | All | All | All |
| Application | Mozilla | Firefox | 3.5.12 | All | All | All |
| Application | Mozilla | Firefox | 3.5.13 | All | All | All |
| Application | Mozilla | Firefox | 3.5.14 | All | All | All |
| Application | Mozilla | Firefox | 3.5.2 | All | All | All |
| Application | Mozilla | Firefox | 3.5.3 | All | All | All |
| Application | Mozilla | Firefox | 3.5.4 | All | All | All |
| Application | Mozilla | Firefox | 3.5.5 | All | All | All |
| Application | Mozilla | Firefox | 3.5.6 | All | All | All |
| Application | Mozilla | Firefox | 3.5.7 | All | All | All |
| Application | Mozilla | Firefox | 3.5.8 | All | All | All |
| Application | Mozilla | Firefox | 3.5.9 | All | All | All |
| Application | Mozilla | Firefox | 3.6 | All | All | All |
| Application | Mozilla | Firefox | 3.6.10 | All | All | All |
| Application | Mozilla | Firefox | 3.6.11 | All | All | All |
| Application | Mozilla | Firefox | 3.6.2 | All | All | All |
| Application | Mozilla | Firefox | 3.6.3 | All | All | All |
| Application | Mozilla | Firefox | 3.6.4 | All | All | All |
| Application | Mozilla | Firefox | 3.6.6 | All | All | All |
| Application | Mozilla | Firefox | 3.6.7 | All | All | All |
| Application | Mozilla | Firefox | 3.6.8 | All | All | All |
| Application | Mozilla | Firefox | 3.6.9 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0 | alpha_1 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | alpha_2 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | alpha_3 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | beta_1 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | beta_2 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | rc1 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | rc2 | All | All |
| Application | Mozilla | Seamonkey | 2.0.1 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.2 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.3 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.4 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.5 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.6 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.7 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.8 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0.9 | All | All | All |
| Application | Mozilla | Thunderbird | 3.0.1 | All | All | All |
| Application | Mozilla | Thunderbird | 3.0.2 | All | All | All |
| Application | Mozilla | Thunderbird | 3.0.3 | All | All | All |
| Application | Mozilla | Thunderbird | 3.0.4 | All | All | All |
| Application | Mozilla | Thunderbird | 3.0.5 | All | All | All |
| Application | Mozilla | Thunderbird | 3.0.6 | All | All | All |
| Application | Mozilla | Thunderbird | 3.0.7 | All | All | All |
| Application | Mozilla | Thunderbird | 3.0.8 | All | All | All |
| Application | Mozilla | Thunderbird | 3.0.9 | All | All | All |
| Application | Mozilla | Thunderbird | 3.1.1 | All | All | All |
| Application | Mozilla | Thunderbird | 3.1.2 | All | All | All |
| Application | Mozilla | Thunderbird | 3.1.3 | All | All | All |
| Application | Mozilla | Thunderbird | 3.1.4 | All | All | All |
| Application | Mozilla | Thunderbird | 3.1.5 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Firefox Memory Corruption Proof of Concept (Simplified) | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit |
| Firefox 3.6.8 - 3.6.11 Interleaving document.write and appendChild Exploit (From the Wild) | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Third Party Advisory |
| Critical vulnerability in Firefox 3.5 and Firefox 3.6 at Mozilla Security Blog | af854a3a-2127-422b-91ae-364da2661108 | blog.mozilla.com | Vendor Advisory |
| Support | Red Hat | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| ASA-2010-311 (RHSA-2010-0808) | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | Third Party Advisory |
| Norman — Proactive IT security | af854a3a-2127-422b-91ae-364da2661108 | www.norman.com | Broken Link |
| Ubuntu update for firefox - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SecurityTracker.com Archives - Mozilla Thunderbird Heap Overflow Lets Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Broken Link |
| SecurityTracker.com Archives - Mozilla Firefox Heap Overflow Lets Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Broken Link |
| Red Hat update for seamonkey - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| USN-1011-3: Xulrunner vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | Third Party Advisory |
| access.redhat.com | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Third Party Advisory |
| Webmail | OVH- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Red Hat update for firefox - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Red Hat update for thunderbird - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| www.cisa.gov/known-exploited-vulnerabilities-catalog | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | www.cisa.gov | US Government Resource |
| SecurityTracker.com Archives - Mozilla Seamonkey Heap Overflow Lets Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Broken Link |
| Firefox Interleaving document.write and appendChild Denial of Service | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit |
| Fedora update for firefox and xulrunner - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Security | af854a3a-2127-422b-91ae-364da2661108 | blogs.sun.com | Broken Link |
| [SECURITY] Fedora 12 Update: galeon-2.0.7-27.fc12 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Third Party Advisory |
| Red Hat update for xulrunner - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Support / Security / Advisories / / MDVSA-2010:219 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | Third Party Advisory |
| 646997 – (CVE-2010-3765) CVE-2010-3765 Firefox race condition flaw (MFSA 2010-73) | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking |
| [SECURITY] Fedora 14 Update: seamonkey-2.0.10-1.fc14 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Third Party Advisory |
| [SECURITY] Fedora 14 Update: galeon-2.0.7-35.fc14.1 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Third Party Advisory |
| The Slackware Linux Project: Slackware Security Advisories | af854a3a-2127-422b-91ae-364da2661108 | slackware.com | Third Party Advisory |
| Support | Red Hat | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| Firefox news | af854a3a-2127-422b-91ae-364da2661108 | isc.sans.edu | Press/Media Coverage |
| Ubuntu update for xulrunner - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail | OVH- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Norman — Proactive IT security | af854a3a-2127-422b-91ae-364da2661108 | www.norman.com | Broken Link |
| Bug 607222 – Interleaving document.write and appendChild can lead to duplicate text frames and overrunning of text run buffers | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | Issue Tracking |
| Bug 607222 – Interleaving document.write and appendChild can lead to duplicate text frames and overrunning of text run buffers | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | Issue Tracking |
| Webmail | OVH- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| Webmail | OVH- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Support | Red Hat | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| Mozilla Firefox 3.5/3.6 Remote Heap Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link |
| MFSA 2010-73: Heap buffer overflow mixing document.write and DOM insertion | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | Third Party Advisory |
| USN-1011-2: Thunderbird vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | Third Party Advisory |
| Support / Security / Advisories / / MDVSA-2010:213 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | Third Party Advisory |
| ASA-2010-312 (RHSA-2010-0810) | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | Third Party Advisory |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Third Party Advisory |
| Oracle Solaris Firefox Multiple Vulnerabilities - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Mozilla Thunderbird "document.write()" and DOM Insertion Vulnerability - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| [SECURITY] Fedora 13 Update: firefox-3.6.12-1.fc13 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Third Party Advisory |
| USN-1011-1: Firefox vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | Third Party Advisory |
| Debian -- Security Information -- DSA-2124-1 xulrunner | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| 404 Page Not Found | af854a3a-2127-422b-91ae-364da2661108 | norman.com | Product |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2025-10-06T00:00:00.000Z | CVE-2010-3765 added to CISA KEV |
There are currently no legacy QID mappings associated with this CVE.