Vulnerability record · CVE-2010-3765 · published 28 October 2010
CVE-2010-3765: Mozilla Firefox, Thunderbird and SeaMonkey memory corruption via appendChild
Mozilla · Firefox
A memory corruption flaw in Mozilla Firefox, Thunderbird and SeaMonkey arises from incorrect index tracking in nsCSSFrameConstructor::ContentAppended when the appendChild method creates multiple frames. With JavaScript enabled, a remote attacker can trigger memory corruption that leads to arbitrary code execution. The flaw was exploited in the wild in October 2010 by the Belmoo malware, making it a confirmed real-world threat rather than a theoretical one.
Description
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, confirmed in-the-wild exploitation by Belmoo, KEV listing and a 0.833 EPSS probability make this an urgent, actively exploited remote code execution flaw.
What it is
A memory corruption flaw in Mozilla Firefox, Thunderbird and SeaMonkey arises from incorrect index tracking in nsCSSFrameConstructor::ContentAppended when the appendChild method creates multiple frames. With JavaScript enabled, a remote attacker can trigger memory corruption that leads to arbitrary code execution. The flaw was exploited in the wild in October 2010 by the Belmoo malware, making it a confirmed real-world threat rather than a theoretical one.
Impact
An attacker gains arbitrary code execution in the context of the affected application, which can lead to full compromise of the user's system. No privileges are required and no user interaction beyond normal browsing or message rendering is needed.
Attack surface
Reached remotely over the network, typically by a user visiting a crafted web page or rendering crafted content in an affected Mozilla product with JavaScript enabled. The CVSS vector shows no authentication and no user interaction requirement, so any path that loads attacker-controlled content is a viable vector.
Exploitation
CVE-2010-3765 is listed in CISA KEV with a 2025-10-06 addition date, and EPSS gives a 30-day probability of 0.833 at the 99.7th percentile. Multiple Exploit-DB entries and the description confirm in-the-wild exploitation by the Belmoo malware in October 2010.
What to do
- Upgrade Firefox, Thunderbird and SeaMonkey to the fixed versions referenced in the Mozilla advisory; this is the only complete fix.
- If immediate upgrade is not possible, disable JavaScript in the affected Mozilla products as a temporary workaround.
- Apply vendor and distribution patches (Fedora, Debian, Slackware, Mandriva advisories) for packaged builds.
- Retire or isolate end-of-life Mozilla 3.5.x, 3.6.x, Thunderbird 3.x and SeaMonkey 2.x installations that cannot be patched.
- Follow CISA BOD 22-01 guidance for any cloud services running affected versions.
Detection
- Hunt for network or proxy logs showing downloads of known Belmoo malware payloads or exploit pages tied to this CVE.
- Monitor endpoint telemetry for browser or mail client processes spawning unexpected child processes or writing executables to user directories.
- Alert on crashes in Firefox, Thunderbird or SeaMonkey with nsCSSFrameConstructor or ContentAppended in the stack trace.
- Inventory hosts still running Firefox 3.5.x/3.6.x, Thunderbird 3.x or SeaMonkey 2.x and flag them for remediation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2010-3765 to the Known Exploited Vulnerabilities catalog on 6 October 2025 as "Mozilla Multiple Products Remote Code Execution Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 27 October 2025.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-3765 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-3765), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.