← Vulnerability feed

Vulnerability record · CVE-2010-3765 · published 28 October 2010

CVE-2010-3765: Mozilla Firefox, Thunderbird and SeaMonkey memory corruption via appendChild

Mozilla · Firefox

A memory corruption flaw in Mozilla Firefox, Thunderbird and SeaMonkey arises from incorrect index tracking in nsCSSFrameConstructor::ContentAppended when the appendChild method creates multiple frames. With JavaScript enabled, a remote attacker can trigger memory corruption that leads to arbitrary code execution. The flaw was exploited in the wild in October 2010 by the Belmoo malware, making it a confirmed real-world threat rather than a theoretical one.

9.8 CVSS 3.1 Critical CISA KEV since 6 Oct 2025 EPSS 83% · top 0.3% CWE-119 · Memory buffer overflow
9.8CVSS 3.1 base score, v2 9.3
83%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
103References, 6 tagged exploit
16 Jun 2026Last modified by NVD

Description

Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8, confirmed in-the-wild exploitation by Belmoo, KEV listing and a 0.833 EPSS probability make this an urgent, actively exploited remote code execution flaw.

What it is

A memory corruption flaw in Mozilla Firefox, Thunderbird and SeaMonkey arises from incorrect index tracking in nsCSSFrameConstructor::ContentAppended when the appendChild method creates multiple frames. With JavaScript enabled, a remote attacker can trigger memory corruption that leads to arbitrary code execution. The flaw was exploited in the wild in October 2010 by the Belmoo malware, making it a confirmed real-world threat rather than a theoretical one.

Impact

An attacker gains arbitrary code execution in the context of the affected application, which can lead to full compromise of the user's system. No privileges are required and no user interaction beyond normal browsing or message rendering is needed.

Attack surface

Reached remotely over the network, typically by a user visiting a crafted web page or rendering crafted content in an affected Mozilla product with JavaScript enabled. The CVSS vector shows no authentication and no user interaction requirement, so any path that loads attacker-controlled content is a viable vector.

Exploitation

CVE-2010-3765 is listed in CISA KEV with a 2025-10-06 addition date, and EPSS gives a 30-day probability of 0.833 at the 99.7th percentile. Multiple Exploit-DB entries and the description confirm in-the-wild exploitation by the Belmoo malware in October 2010.

What to do

  • Upgrade Firefox, Thunderbird and SeaMonkey to the fixed versions referenced in the Mozilla advisory; this is the only complete fix.
  • If immediate upgrade is not possible, disable JavaScript in the affected Mozilla products as a temporary workaround.
  • Apply vendor and distribution patches (Fedora, Debian, Slackware, Mandriva advisories) for packaged builds.
  • Retire or isolate end-of-life Mozilla 3.5.x, 3.6.x, Thunderbird 3.x and SeaMonkey 2.x installations that cannot be patched.
  • Follow CISA BOD 22-01 guidance for any cloud services running affected versions.

Detection

  • Hunt for network or proxy logs showing downloads of known Belmoo malware payloads or exploit pages tied to this CVE.
  • Monitor endpoint telemetry for browser or mail client processes spawning unexpected child processes or writing executables to user directories.
  • Alert on crashes in Firefox, Thunderbird or SeaMonkey with nsCSSFrameConstructor or ContentAppended in the stack trace.
  • Inventory hosts still running Firefox 3.5.x/3.6.x, Thunderbird 3.x or SeaMonkey 2.x and flag them for remediation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2010-3765 to the Known Exploited Vulnerabilities catalog on 6 October 2025 as "Mozilla Multiple Products Remote Code Execution Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 27 October 2025.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://blog.mozilla.com/security/2010/10/26/critical-vulnerability-in-firefox-3-5-and-firefox-3-6/ Vendor Advisory
http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozilla_firefox Broken Link
http://isc.sans.edu/diary.html?storyid=9817 Press/Media Coverage
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050233.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050061.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050077.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050154.html Third Party Advisory
http://norman.com/about_norman/press_center/news_archive/2010/129223/en?utm_source=twitterfeed&utm_medium=twitter Product
http://secunia.com/advisories/41761 Vendor Advisory
http://secunia.com/advisories/41965 Vendor Advisory
http://secunia.com/advisories/41966 Vendor Advisory
http://secunia.com/advisories/41969 Vendor Advisory
http://secunia.com/advisories/41975 Vendor Advisory
http://secunia.com/advisories/42003 Vendor Advisory
http://secunia.com/advisories/42008 Vendor Advisory
http://secunia.com/advisories/42043 Vendor Advisory
http://secunia.com/advisories/42867 Vendor Advisory
http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.556706 Third Party Advisory
http://support.avaya.com/css/P8/documents/100114329 Third Party Advisory
http://support.avaya.com/css/P8/documents/100114335 Third Party Advisory
http://www.debian.org/security/2010/dsa-2124 Third Party Advisory
http://www.exploit-db.com/exploits/15341 Exploit
http://www.exploit-db.com/exploits/15342 Exploit
http://www.exploit-db.com/exploits/15352 Exploit
http://www.mandriva.com/security/advisories?name=MDVSA-2010:213 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2010:219 Third Party Advisory
http://www.mozilla.org/security/announce/2010/mfsa2010-73.html Third Party Advisory
http://www.norman.com/about_norman/press_center/news_archive/2010/129223/ Broken Link
http://www.norman.com/security_center/virus_description_archive/129146/ Broken Link
http://www.redhat.com/support/errata/RHSA-2010-0808.html Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2010-0809.html Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2010-0810.html Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2010-0861.html Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2010-0896.html Third Party Advisory
http://www.securityfocus.com/bid/44425 Broken Link
http://www.securitytracker.com/id?1024645 Broken Link
http://www.securitytracker.com/id?1024650 Broken Link
http://www.securitytracker.com/id?1024651 Broken Link
http://www.ubuntu.com/usn/USN-1011-2 Third Party Advisory
http://www.ubuntu.com/usn/USN-1011-3 Third Party Advisory

Track CVE-2010-3765 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2019-11708Mozilla Firefox and Thunderbird sandbox escape via Prompt:Open IPC validation flawThe Prompt:Open IPC message between child and parent processes does not sufficiently vet its parameters, letting a compromised child process cause th…KEVEPSS 56%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed9.6CVE-2022-26486Firefox WebGPU IPC use-after-free enables sandbox escapeAn unexpected message in the WebGPU IPC framework triggers a use-after-free in Mozilla Firefox, Firefox ESR, Firefox for Android, Thunderbird and Foc…KEVEPSS 2.3%analysed8.8CVE-2023-5217libvpx VP8 encoding heap buffer overflow exploited via crafted HTMLA heap buffer overflow in the VP8 encoder in libvpx affects Google Chrome before 117.0.5938.132 and libvpx 1.13.1, and is reachable through a crafted…KEVEPSS 49%analysed8.8CVE-2023-4863libwebp Heap Buffer Overflow via Crafted WebP ImageA heap buffer overflow in libwebp allows an out-of-bounds memory write when processing a crafted WebP image. It affects Google Chrome before 116.0.58…KEVEPSS 100%analysed8.8CVE-2022-26485Firefox XSLT parameter removal use-after-freeRemoving an XSLT parameter during processing in Mozilla Firefox could trigger a use-after-free condition. Mozilla reported attacks in the wild abusin…KEVEPSS 14%analysed8.8CVE-2019-17026Firefox and Thunderbird IonMonkey JIT type confusionIncorrect alias information in the IonMonkey JIT compiler when setting array elements can cause a type confusion in Firefox, Firefox ESR and Thunderb…KEVEPSS 46%analysed8.8CVE-2019-11707Mozilla Firefox and Thunderbird Array.pop type confusionA type confusion flaw in JavaScript Array.pop handling lets a crafted script corrupt object types in the browser engine, producing an exploitable cra…KEVEPSS 38%analysed

Source: NIST National Vulnerability Database (record CVE-2010-3765), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.