CVE-2010-3765

KEV
Published: Ott 28, 2010 Last Modified: Ott 22, 2025
ExploitDB:
Other exploit source:
Google Dorks:
CRITICAL 9,8
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high
HIGH 9,3
Access Vector: network
Access Complexity: medium
Authentication: none
Confidentiality: complete
Integrity: complete
Availability: complete

Description

AI Translation Available

Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,8795
Percentile
1,0th
Updated

EPSS Score Trend (Last 90 Days)

119

Improper Restriction of Operations within the Bounds of a Memory Buffer

Stable
Common Consequences
Security Scopes Affected:
Integrity Confidentiality Availability
Potential Impacts:
Execute Unauthorized Code Or Commands Modify Memory Read Memory Dos: Crash, Exit, Or Restart Dos: Resource Consumption (Cpu) Dos: Resource Consumption (Memory)
Applicable Platforms
Languages: Assembly, C, C++, Memory-Unsafe
View CWE Details
Exploit

Mozilla Firefox - Interleaving 'document.write' / 'appendChild' Denial …

Verified

Mozilla Firefox - Interleaving 'document.write' / 'appendChild' Denial of Service

View Exploit Code →
Exploit

Mozilla Firefox - Simplified Memory Corruption (PoC)

Verified

Mozilla Firefox - Simplified Memory Corruption (PoC)

View Exploit Code →
Exploit

Mozilla Firefox 3.6.8 < 3.6.11 - Interleaving 'document.write' …

Verified

Mozilla Firefox 3.6.8 < 3.6.11 - Interleaving 'document.write' / 'appendChild' Remote Overflow

View Exploit Code →
Exploit

Mozilla Firefox - Interleaving 'document.write' / 'appendChild' (Metasploit)

Verified Metasploit Framework (MSF)

Mozilla Firefox - Interleaving 'document.write' / 'appendChild' (Metasploit)

View Exploit Code →
Application

Firefox by Mozilla

cpe:2.3:a:mozilla:firefox:3.5.1:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Thunderbird by Mozilla

cpe:2.3:a:mozilla:thunderbird:3.0.2:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Firefox by Mozilla

cpe:2.3:a:mozilla:firefox:3.6.11:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Firefox by Mozilla

cpe:2.3:a:mozilla:firefox:3.5.12:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Seamonkey by Mozilla

cpe:2.3:a:mozilla:seamonkey:2.0.4:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Thunderbird by Mozilla

cpe:2.3:a:mozilla:thunderbird:3.1.1:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Firefox by Mozilla

cpe:2.3:a:mozilla:firefox:3.5.8:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Thunderbird by Mozilla

cpe:2.3:a:mozilla:thunderbird:3.1.3:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Firefox by Mozilla

cpe:2.3:a:mozilla:firefox:3.6.2:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Seamonkey by Mozilla

cpe:2.3:a:mozilla:seamonkey:2.0.7:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Seamonkey by Mozilla

cpe:2.3:a:mozilla:seamonkey:2.0.2:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Firefox by Mozilla

cpe:2.3:a:mozilla:firefox:3.5.7:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Seamonkey by Mozilla

cpe:2.3:a:mozilla:seamonkey:2.0.8:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Firefox by Mozilla

cpe:2.3:a:mozilla:firefox:3.5.3:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Thunderbird by Mozilla

cpe:2.3:a:mozilla:thunderbird:3.0.9:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Firefox by Mozilla

cpe:2.3:a:mozilla:firefox:3.5.14:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Thunderbird by Mozilla

cpe:2.3:a:mozilla:thunderbird:3.0.1:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Firefox by Mozilla

cpe:2.3:a:mozilla:firefox:3.6.7:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Firefox by Mozilla

cpe:2.3:a:mozilla:firefox:3.6.8:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Seamonkey by Mozilla

cpe:2.3:a:mozilla:seamonkey:2.0:rc1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Firefox by Mozilla

cpe:2.3:a:mozilla:firefox:3.5.2:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Seamonkey by Mozilla

cpe:2.3:a:mozilla:seamonkey:2.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Firefox by Mozilla

cpe:2.3:a:mozilla:firefox:3.5.13:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Seamonkey by Mozilla

cpe:2.3:a:mozilla:seamonkey:2.0:alpha_2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Thunderbird by Mozilla

cpe:2.3:a:mozilla:thunderbird:3.0.5:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Firefox by Mozilla

cpe:2.3:a:mozilla:firefox:3.6.10:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Thunderbird by Mozilla

cpe:2.3:a:mozilla:thunderbird:3.0.3:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Firefox by Mozilla

cpe:2.3:a:mozilla:firefox:3.5:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Seamonkey by Mozilla

cpe:2.3:a:mozilla:seamonkey:2.0.9:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Seamonkey by Mozilla

cpe:2.3:a:mozilla:seamonkey:2.0:rc2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Thunderbird by Mozilla

cpe:2.3:a:mozilla:thunderbird:3.1.2:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Thunderbird by Mozilla

cpe:2.3:a:mozilla:thunderbird:3.0.8:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Thunderbird by Mozilla

cpe:2.3:a:mozilla:thunderbird:3.1.4:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Seamonkey by Mozilla

cpe:2.3:a:mozilla:seamonkey:2.0:beta_1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Seamonkey by Mozilla

cpe:2.3:a:mozilla:seamonkey:2.0.5:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Thunderbird by Mozilla

cpe:2.3:a:mozilla:thunderbird:3.0.6:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Firefox by Mozilla

cpe:2.3:a:mozilla:firefox:3.6.3:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Seamonkey by Mozilla

cpe:2.3:a:mozilla:seamonkey:2.0.3:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Firefox by Mozilla

cpe:2.3:a:mozilla:firefox:3.5.10:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Firefox by Mozilla

cpe:2.3:a:mozilla:firefox:3.5.6:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Seamonkey by Mozilla

cpe:2.3:a:mozilla:seamonkey:2.0:alpha_1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Firefox by Mozilla

cpe:2.3:a:mozilla:firefox:3.6.9:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Seamonkey by Mozilla

cpe:2.3:a:mozilla:seamonkey:2.0.6:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Firefox by Mozilla

cpe:2.3:a:mozilla:firefox:3.6.4:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Thunderbird by Mozilla

cpe:2.3:a:mozilla:thunderbird:3.0.4:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Firefox by Mozilla

cpe:2.3:a:mozilla:firefox:3.6.6:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Seamonkey by Mozilla

cpe:2.3:a:mozilla:seamonkey:2.0.1:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Firefox by Mozilla

cpe:2.3:a:mozilla:firefox:3.5.4:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Thunderbird by Mozilla

cpe:2.3:a:mozilla:thunderbird:3.0.7:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Thunderbird by Mozilla

cpe:2.3:a:mozilla:thunderbird:3.1.5:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Firefox by Mozilla

cpe:2.3:a:mozilla:firefox:3.5.9:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Seamonkey by Mozilla

cpe:2.3:a:mozilla:seamonkey:2.0:beta_2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Firefox by Mozilla

cpe:2.3:a:mozilla:firefox:3.5.5:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Firefox by Mozilla

cpe:2.3:a:mozilla:firefox:3.6:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Firefox by Mozilla

cpe:2.3:a:mozilla:firefox:3.5.11:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Seamonkey by Mozilla

cpe:2.3:a:mozilla:seamonkey:2.0:alpha_3:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010…
http://blog.mozilla.com/security/2010/10/26/critical-vulnerability-in-firefox-3…
http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozilla_firefox
http://isc.sans.edu/diary.html?storyid=9817
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050233.…
http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050061.h…
http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050077.h…
http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050154.h…
http://norman.com/about_norman/press_center/news_archive/2010/129223/en?utm_sou…
https://bugzilla.mozilla.org/show_bug.cgi?id=607222
https://bugzilla.mozilla.org/show_bug.cgi?id=607222#c53
https://bugzilla.redhat.com/show_bug.cgi?id=646997
http://secunia.com/advisories/41761
http://secunia.com/advisories/41965
http://secunia.com/advisories/41966
http://secunia.com/advisories/41969
http://secunia.com/advisories/41975
http://secunia.com/advisories/42003
http://secunia.com/advisories/42008
http://secunia.com/advisories/42043
http://secunia.com/advisories/42867
http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackwar…
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%…
https://rhn.redhat.com/errata/RHSA-2010-0812.html
http://support.avaya.com/css/P8/documents/100114329
http://support.avaya.com/css/P8/documents/100114335
http://www.debian.org/security/2010/dsa-2124
http://www.exploit-db.com/exploits/15341
http://www.exploit-db.com/exploits/15342
http://www.exploit-db.com/exploits/15352
http://www.mandriva.com/security/advisories?name=MDVSA-2010:213
http://www.mandriva.com/security/advisories?name=MDVSA-2010:219
http://www.mozilla.org/security/announce/2010/mfsa2010-73.html
http://www.norman.com/about_norman/press_center/news_archive/2010/129223/
http://www.norman.com/security_center/virus_description_archive/129146/
http://www.redhat.com/support/errata/RHSA-2010-0808.html
http://www.redhat.com/support/errata/RHSA-2010-0809.html
http://www.redhat.com/support/errata/RHSA-2010-0810.html
http://www.redhat.com/support/errata/RHSA-2010-0861.html
http://www.redhat.com/support/errata/RHSA-2010-0896.html
http://www.securityfocus.com/bid/44425
http://www.securitytracker.com/id?1024645
http://www.securitytracker.com/id?1024650
http://www.securitytracker.com/id?1024651
http://www.ubuntu.com/usn/usn-1011-1
http://www.ubuntu.com/usn/USN-1011-2
http://www.ubuntu.com/usn/USN-1011-3
http://www.vupen.com/english/advisories/2010/2837
http://www.vupen.com/english/advisories/2010/2857
http://www.vupen.com/english/advisories/2010/2864
http://www.vupen.com/english/advisories/2010/2871
http://www.vupen.com/english/advisories/2011/0061
http://blog.mozilla.com/security/2010/10/26/critical-vulnerability-in-firefox-3…
http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozilla_firefox
http://isc.sans.edu/diary.html?storyid=9817
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050233.…
http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050061.h…
http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050077.h…
http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050154.h…
http://norman.com/about_norman/press_center/news_archive/2010/129223/en?utm_sou…
https://bugzilla.mozilla.org/show_bug.cgi?id=607222
https://bugzilla.mozilla.org/show_bug.cgi?id=607222#c53
https://bugzilla.redhat.com/show_bug.cgi?id=646997
http://secunia.com/advisories/41761
http://secunia.com/advisories/41965
http://secunia.com/advisories/41966
http://secunia.com/advisories/41969
http://secunia.com/advisories/41975
http://secunia.com/advisories/42003
http://secunia.com/advisories/42008
http://secunia.com/advisories/42043
http://secunia.com/advisories/42867
http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackwar…
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%…
https://rhn.redhat.com/errata/RHSA-2010-0812.html
http://support.avaya.com/css/P8/documents/100114329
http://support.avaya.com/css/P8/documents/100114335
http://www.debian.org/security/2010/dsa-2124
http://www.exploit-db.com/exploits/15341
http://www.exploit-db.com/exploits/15342
http://www.exploit-db.com/exploits/15352
http://www.mandriva.com/security/advisories?name=MDVSA-2010:213
http://www.mandriva.com/security/advisories?name=MDVSA-2010:219
http://www.mozilla.org/security/announce/2010/mfsa2010-73.html
http://www.norman.com/about_norman/press_center/news_archive/2010/129223/
http://www.norman.com/security_center/virus_description_archive/129146/
http://www.redhat.com/support/errata/RHSA-2010-0808.html
http://www.redhat.com/support/errata/RHSA-2010-0809.html
http://www.redhat.com/support/errata/RHSA-2010-0810.html
http://www.redhat.com/support/errata/RHSA-2010-0861.html
http://www.redhat.com/support/errata/RHSA-2010-0896.html
http://www.securityfocus.com/bid/44425
http://www.securitytracker.com/id?1024645
http://www.securitytracker.com/id?1024650
http://www.securitytracker.com/id?1024651
http://www.ubuntu.com/usn/usn-1011-1
http://www.ubuntu.com/usn/USN-1011-2
http://www.ubuntu.com/usn/USN-1011-3
http://www.vupen.com/english/advisories/2010/2837
http://www.vupen.com/english/advisories/2010/2857
http://www.vupen.com/english/advisories/2010/2864
http://www.vupen.com/english/advisories/2010/2871
http://www.vupen.com/english/advisories/2011/0061