V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2010-3765
DEB
Critical KEVConfirmedExploit available

Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x be…

CVSS
9.8
Critical
EPSS
0.83
p99
Published
2010-01-01
Updated
2025-10-06
Description

Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware.

Tags · CWE
KEVRCEPre-auth
CWE-119
CAPEC-8
CAPEC-9
CAPEC-10
CAPEC-14
CAPEC-24
CAPEC-42
CAPEC-44
CAPEC-45
CAPEC-46
CAPEC-47
CAPEC-100
CAPEC-123
Affected products
FirefoxFirefoxFirefoxFirefox-3.0IceapeIceapeIcedoveIcedoveIceweaselIceweaselSeamonkeySeamonkeySeamonkeyThunderbirdThunderbirdThunderbirdThunderbirdXulrunnerXulrunnerXulrunner
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2010-01-01
Published
2025-10-06
Added to KEV
2025-10-06
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.833 · p99
Known exploited (KEV)
Yes
Known exploits — Сканер-ВС
CVE-2010-3765
cisa · https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Enterprise
15341
exploitdb · https://www.exploit-db.com/exploits/15341
Enterprise
15342
exploitdb · https://www.exploit-db.com/exploits/15342
Enterprise
15352
exploitdb · https://www.exploit-db.com/exploits/15352
Enterprise
16509
exploitdb · https://www.exploit-db.com/exploits/16509
Enterprise
Affected products
ProductVendorStatus
firefoxExploited
firefoxExploited
firefoxExploited
firefox-3.0Exploited
iceapeExploited
iceapeExploited
icedoveExploited
icedoveExploited
iceweaselExploited
iceweaselExploited
seamonkeyExploited
seamonkeyExploited
seamonkeyExploited
thunderbirdExploited
thunderbirdExploited
thunderbirdExploited
thunderbirdExploited
xulrunnerExploited
xulrunnerExploited
xulrunnerExploited
Showing first 20 of 26
Source databases
DEB
CVE
RED
UBU