CVE-2010-3765

CRITICAL KEV

Mozilla Firefox - Memory Corruption

Title source: rule

Description

Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware.

Exploits (5)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16509
exploitdb WORKING POC VERIFIED
by anonymous · htmlremotewindows
https://www.exploit-db.com/exploits/15352
exploitdb WORKING POC VERIFIED
by extraexploit · htmldosmultiple
https://www.exploit-db.com/exploits/15342
exploitdb WORKING POC VERIFIED
by Daniel Veditz · htmldosmultiple
https://www.exploit-db.com/exploits/15341
metasploit WORKING POC NORMAL
by unknown, scriptjunkie · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/mozilla_interleaved_write.rb

Scores

CVSS v3 9.8
EPSS 0.8662
EPSS Percentile 99.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2025-10-06
VulnCheck KEV 2010-10-27
InTheWild.io 2017-09-19
ENISA EUVD EUVD-2010-3744
CWE
CWE-119
Status published
Products (43)
mozilla/firefox 3.5
mozilla/firefox 3.5.1
mozilla/firefox 3.5.2
mozilla/firefox 3.5.3
mozilla/firefox 3.5.4
mozilla/firefox 3.5.5
mozilla/firefox 3.5.6
mozilla/firefox 3.5.7
mozilla/firefox 3.5.8
mozilla/firefox 3.5.9
... and 33 more
Published Oct 28, 2010
KEV Added Oct 06, 2025
Tracked Since Feb 18, 2026