CVE-2010-3765
CRITICAL KEVMozilla Firefox - Memory Corruption
Title source: ruleDescription
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware.
Exploits (5)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16509
exploitdb
WORKING POC
VERIFIED
by anonymous · htmlremotewindows
https://www.exploit-db.com/exploits/15352
exploitdb
WORKING POC
VERIFIED
by extraexploit · htmldosmultiple
https://www.exploit-db.com/exploits/15342
exploitdb
WORKING POC
VERIFIED
by Daniel Veditz · htmldosmultiple
https://www.exploit-db.com/exploits/15341
metasploit
WORKING POC
NORMAL
by unknown, scriptjunkie · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/mozilla_interleaved_write.rb
References (52)
... and 32 more
Scores
CVSS v3
9.8
EPSS
0.8662
EPSS Percentile
99.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2025-10-06
VulnCheck KEV
2010-10-27
InTheWild.io
2017-09-19
ENISA EUVD
EUVD-2010-3744
CWE
CWE-119
Status
published
Products (43)
mozilla/firefox
3.5
mozilla/firefox
3.5.1
mozilla/firefox
3.5.2
mozilla/firefox
3.5.3
mozilla/firefox
3.5.4
mozilla/firefox
3.5.5
mozilla/firefox
3.5.6
mozilla/firefox
3.5.7
mozilla/firefox
3.5.8
mozilla/firefox
3.5.9
... and 33 more
Published
Oct 28, 2010
KEV Added
Oct 06, 2025
Tracked Since
Feb 18, 2026