CVE-2010-3765
Confirmed PUBLISHEDMozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before...
5697 days faster than CISA KEV
Recommended Action
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
At a Glance
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware.
- CVE Published
- Oct 27, 2010
- Exploitation Reported
- Oct 27, 2010
- CVSS
- 9.8 Critical
- EPSS
- 83.3%
Affected Versions
| Vendor | Product | Version | Status |
|---|---|---|---|
| n/a |
n/a
|
n/a |
Affected |
CVE References
- RHSA-2010:0812 rhn.redhat.com · Vendor Advisory https://rhn.redhat.com/errata/RHSA-2010-0812.html
- RHSA-2010:0896 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2010-0896.html
- RHSA-2010:0808 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2010-0808.html
- FEDORA-2010-17105 lists.fedoraproject.org · Vendor Advisory http://lists.fedoraproject.org/pipermail/package-announce/2010-Novemb...
- USN-1011-3 ubuntu.com · Vendor Advisory http://www.ubuntu.com/usn/USN-1011-3
Show 46 more references
- USN-1011-1 ubuntu.com · Vendor Advisory http://www.ubuntu.com/usn/usn-1011-1
- USN-1011-2 ubuntu.com · Vendor Advisory http://www.ubuntu.com/usn/USN-1011-2
- RHSA-2010:0809 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2010-0809.html
- MDVSA-2010:219 mandriva.com · Vendor Advisory http://www.mandriva.com/security/advisories?name=MDVSA-2010:219
- DSA-2124 debian.org · Vendor Advisory http://www.debian.org/security/2010/dsa-2124
- MDVSA-2010:213 mandriva.com · Vendor Advisory http://www.mandriva.com/security/advisories?name=MDVSA-2010:213
- FEDORA-2010-16883 lists.fedoraproject.org · Vendor Advisory http://lists.fedoraproject.org/pipermail/package-announce/2010-Octobe...
- SSA:2010-305-01 slackware.com · Vendor Advisory http://slackware.com/security/viewer.php?l=slackware-security&y=2010&...
- RHSA-2010:0810 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2010-0810.html
- FEDORA-2010-16897 lists.fedoraproject.org · Vendor Advisory http://lists.fedoraproject.org/pipermail/package-announce/2010-Octobe...
- RHSA-2010:0861 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2010-0861.html
- FEDORA-2010-16885 lists.fedoraproject.org · Vendor Advisory http://lists.fedoraproject.org/pipermail/package-announce/2010-Octobe...
- 41965 secunia.com · Third-Party Advisory http://secunia.com/advisories/41965
- 41975 secunia.com · Third-Party Advisory http://secunia.com/advisories/41975
- 41761 secunia.com · Third-Party Advisory http://secunia.com/advisories/41761
- 41969 secunia.com · Third-Party Advisory http://secunia.com/advisories/41969
- 42867 secunia.com · Third-Party Advisory http://secunia.com/advisories/42867
- 42043 secunia.com · Third-Party Advisory http://secunia.com/advisories/42043
- 41966 secunia.com · Third-Party Advisory http://secunia.com/advisories/41966
- 42008 secunia.com · Third-Party Advisory http://secunia.com/advisories/42008
- 42003 secunia.com · Third-Party Advisory http://secunia.com/advisories/42003
- 15341 exploit-db.com · Exploit http://www.exploit-db.com/exploits/15341
- 15352 exploit-db.com · Exploit http://www.exploit-db.com/exploits/15352
- 15342 exploit-db.com · Exploit http://www.exploit-db.com/exploits/15342
- 44425 securityfocus.com · VDB Entry http://www.securityfocus.com/bid/44425
- ADV-2010-2837 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2010/2837
- 1024651 securitytracker.com · VDB Entry http://www.securitytracker.com/id?1024651
- 1024650 securitytracker.com · VDB Entry http://www.securitytracker.com/id?1024650
- ADV-2010-2857 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2010/2857
- ADV-2011-0061 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2011/0061
- 1024645 securitytracker.com · VDB Entry http://www.securitytracker.com/id?1024645
- ADV-2010-2871 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2010/2871
- oval:org.mitre.oval:def:12108 oval.cisecurity.org · VDB Entry https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.m...
- ADV-2010-2864 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2010/2864
- bugzilla.mozilla.org/show_bug.cgi bugzilla.mozilla.org · CVE Record https://bugzilla.mozilla.org/show_bug.cgi?id=607222#c53
- bugzilla.redhat.com/show_bug.cgi bugzilla.redhat.com · CVE Record https://bugzilla.redhat.com/show_bug.cgi?id=646997
- support.avaya.com/css/P8/documents/100114335 support.avaya.com · CVE Record http://support.avaya.com/css/P8/documents/100114335
- bugzilla.mozilla.org/show_bug.cgi bugzilla.mozilla.org · CVE Record https://bugzilla.mozilla.org/show_bug.cgi?id=607222
- norman.com/about_norman/press_center/news_archive/2010/... norman.com · CVE Record http://norman.com/about_norman/press_center/news_archive/2010/129223/...
- blogs.sun.com/security/entry/multiple_vulnerabilities_in_m... blogs.sun.com · CVE Record http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozil...
- norman.com/about_norman/press_center/news_archive/2010/... norman.com · CVE Record http://www.norman.com/about_norman/press_center/news_archive/2010/129...
- blog.mozilla.com/security/2010/10/26/critical-vulnerability-i... blog.mozilla.com · CVE Record http://blog.mozilla.com/security/2010/10/26/critical-vulnerability-in...
- support.avaya.com/css/P8/documents/100114329 support.avaya.com · CVE Record http://support.avaya.com/css/P8/documents/100114329
- norman.com/security_center/virus_description_archive/12... norman.com · CVE Record http://www.norman.com/security_center/virus_description_archive/129146/
- isc.sans.edu/diary.html isc.sans.edu · CVE Record http://isc.sans.edu/diary.html?storyid=9817
- mozilla.org/security/announce/2010/mfsa2010-73.html mozilla.org · CVE Record http://www.mozilla.org/security/announce/2010/mfsa2010-73.html
Recommended Actions
- Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
- Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
- Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.
Known Exploited Vulnerability Sources
Catalogues that list this CVE as a known exploited vulnerability.
Per-source evidence links for KEV attestations are available through the KEVIntel Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| CVE First | 2010-10-27 22:00 UTC |
| CISA | 2026-06-02 14:05 UTC |
Scanner Artifacts
Nuclei and Metasploit references linked to this CVE.
| Scanner | Reference | Detected |
|---|---|---|
| Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/mozilla_interleaved_write.rb | Apr 28, 2025 |
Virtual Patch
Compensating WAF rules to help reduce exposure to this CVE. Rule content and deployable vendor exports are available with KEVIntel Enterprise.
KEVIntel does not currently have a virtual patch for this CVE. When available, KEVIntel virtual patches ship as deployable ModSecurity, Cloudflare, and AWS WAF rules.
Enterprise feature. Virtual patch rule content and deployable vendor exports (ModSecurity, Cloudflare, AWS WAF) are available to KEVIntel Enterprise users.
CVSS Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitation Status
Exploited in the wild
Recorded 2010-10-27 22:00:00 UTC · CVE
Proof of concept available
Recorded 2025-04-28 15:02:40 UTC
Weaknesses (CWE)
-
Improper Restriction of Operations within the Bounds of a Memory Buffer
Scanner Integrations
| Scanner | Reference | Detected |
|---|---|---|
| Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/mozilla_interleaved_write.rb | Apr 28, 2025 |
Potential Proof of Concepts
These PoCs are unverified and could contain malware. Use at your own risk.
Timeline
Key exploitation, disclosure, scanner coverage, and KEV attestation events for this CVE.
-
14:05 UTC about 2 months ago14:05 UTC · about 2 months ago
Added to CISA KEV
Listed in the CISA Known Exploited Vulnerabilities catalog
-
15:02 UTC about 1 year ago15:02 UTC · about 1 year ago
Metasploit module available
Exploit module available
-
15:02 UTC about 1 year ago15:02 UTC · about 1 year ago
Public PoC available
Public proof-of-concept code published
-
22:00 UTC over 15 years ago22:00 UTC · over 15 years ago
Added to KEVIntel KEV Feed
High-confidence, third-party attested exploitation
-
22:00 UTC over 15 years ago22:00 UTC · over 15 years ago
CVE published
Vulnerability disclosed publicly
-
00:00 UTC almost 16 years ago00:00 UTC · almost 16 years ago
CVE ID reserved
Identifier reserved by the CNA
Automate This Intelligence with the Pro API
Confidence scoring, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
Pro API Example
GET /api/v2/pro/kevs/CVE-2010-3765
{
"cve_id": "CVE-2010-3765",
"title": "Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3....",
"affected_vendor": "Mozilla",
"affected_product": "Firefox, Thunderbird, SeaMonkey",
"affected_versions": [
{ "vendor": "...", "product": "...", "status": "affected", "display_label": "..." }
],
"confidence": "Confirmed",
"cvss_score": 9.8,
"epss_score": 0.83279,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "...": "Pro API fields" },
"proof_of_concepts": [ "..." ],
"scanner_integrations": [ "..." ]
}