CVE-2010-3765

Confirmed PUBLISHED

Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before...

Mozilla · Firefox, Thunderbird, SeaMonkey

5697 days faster than CISA KEV

Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.8 Critical EPSS 83.3%

At a Glance

Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware.

java cisa metasploit
CVE Published
Oct 27, 2010
Exploitation Reported
Oct 27, 2010
CVSS
9.8 Critical
EPSS
83.3%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • RHSA-2010:0812 rhn.redhat.com · Vendor Advisory https://rhn.redhat.com/errata/RHSA-2010-0812.html
  • RHSA-2010:0896 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2010-0896.html
  • RHSA-2010:0808 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2010-0808.html
  • FEDORA-2010-17105 lists.fedoraproject.org · Vendor Advisory http://lists.fedoraproject.org/pipermail/package-announce/2010-Novemb...
  • USN-1011-3 ubuntu.com · Vendor Advisory http://www.ubuntu.com/usn/USN-1011-3
Show 46 more references
  • USN-1011-1 ubuntu.com · Vendor Advisory http://www.ubuntu.com/usn/usn-1011-1
  • USN-1011-2 ubuntu.com · Vendor Advisory http://www.ubuntu.com/usn/USN-1011-2
  • RHSA-2010:0809 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2010-0809.html
  • MDVSA-2010:219 mandriva.com · Vendor Advisory http://www.mandriva.com/security/advisories?name=MDVSA-2010:219
  • DSA-2124 debian.org · Vendor Advisory http://www.debian.org/security/2010/dsa-2124
  • MDVSA-2010:213 mandriva.com · Vendor Advisory http://www.mandriva.com/security/advisories?name=MDVSA-2010:213
  • FEDORA-2010-16883 lists.fedoraproject.org · Vendor Advisory http://lists.fedoraproject.org/pipermail/package-announce/2010-Octobe...
  • SSA:2010-305-01 slackware.com · Vendor Advisory http://slackware.com/security/viewer.php?l=slackware-security&y=2010&...
  • RHSA-2010:0810 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2010-0810.html
  • FEDORA-2010-16897 lists.fedoraproject.org · Vendor Advisory http://lists.fedoraproject.org/pipermail/package-announce/2010-Octobe...
  • RHSA-2010:0861 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2010-0861.html
  • FEDORA-2010-16885 lists.fedoraproject.org · Vendor Advisory http://lists.fedoraproject.org/pipermail/package-announce/2010-Octobe...
  • 41965 secunia.com · Third-Party Advisory http://secunia.com/advisories/41965
  • 41975 secunia.com · Third-Party Advisory http://secunia.com/advisories/41975
  • 41761 secunia.com · Third-Party Advisory http://secunia.com/advisories/41761
  • 41969 secunia.com · Third-Party Advisory http://secunia.com/advisories/41969
  • 42867 secunia.com · Third-Party Advisory http://secunia.com/advisories/42867
  • 42043 secunia.com · Third-Party Advisory http://secunia.com/advisories/42043
  • 41966 secunia.com · Third-Party Advisory http://secunia.com/advisories/41966
  • 42008 secunia.com · Third-Party Advisory http://secunia.com/advisories/42008
  • 42003 secunia.com · Third-Party Advisory http://secunia.com/advisories/42003
  • 15341 exploit-db.com · Exploit http://www.exploit-db.com/exploits/15341
  • 15352 exploit-db.com · Exploit http://www.exploit-db.com/exploits/15352
  • 15342 exploit-db.com · Exploit http://www.exploit-db.com/exploits/15342
  • 44425 securityfocus.com · VDB Entry http://www.securityfocus.com/bid/44425
  • ADV-2010-2837 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2010/2837
  • 1024651 securitytracker.com · VDB Entry http://www.securitytracker.com/id?1024651
  • 1024650 securitytracker.com · VDB Entry http://www.securitytracker.com/id?1024650
  • ADV-2010-2857 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2010/2857
  • ADV-2011-0061 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2011/0061
  • 1024645 securitytracker.com · VDB Entry http://www.securitytracker.com/id?1024645
  • ADV-2010-2871 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2010/2871
  • oval:org.mitre.oval:def:12108 oval.cisecurity.org · VDB Entry https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.m...
  • ADV-2010-2864 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2010/2864
  • bugzilla.mozilla.org/show_bug.cgi bugzilla.mozilla.org · CVE Record https://bugzilla.mozilla.org/show_bug.cgi?id=607222#c53
  • bugzilla.redhat.com/show_bug.cgi bugzilla.redhat.com · CVE Record https://bugzilla.redhat.com/show_bug.cgi?id=646997
  • support.avaya.com/css/P8/documents/100114335 support.avaya.com · CVE Record http://support.avaya.com/css/P8/documents/100114335
  • bugzilla.mozilla.org/show_bug.cgi bugzilla.mozilla.org · CVE Record https://bugzilla.mozilla.org/show_bug.cgi?id=607222
  • norman.com/about_norman/press_center/news_archive/2010/... norman.com · CVE Record http://norman.com/about_norman/press_center/news_archive/2010/129223/...
  • blogs.sun.com/security/entry/multiple_vulnerabilities_in_m... blogs.sun.com · CVE Record http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozil...
  • norman.com/about_norman/press_center/news_archive/2010/... norman.com · CVE Record http://www.norman.com/about_norman/press_center/news_archive/2010/129...
  • blog.mozilla.com/security/2010/10/26/critical-vulnerability-i... blog.mozilla.com · CVE Record http://blog.mozilla.com/security/2010/10/26/critical-vulnerability-in...
  • support.avaya.com/css/P8/documents/100114329 support.avaya.com · CVE Record http://support.avaya.com/css/P8/documents/100114329
  • norman.com/security_center/virus_description_archive/12... norman.com · CVE Record http://www.norman.com/security_center/virus_description_archive/129146/
  • isc.sans.edu/diary.html isc.sans.edu · CVE Record http://isc.sans.edu/diary.html?storyid=9817
  • mozilla.org/security/announce/2010/mfsa2010-73.html mozilla.org · CVE Record http://www.mozilla.org/security/announce/2010/mfsa2010-73.html

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.