Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware.
Conclusion & alert: CVE-2010-3765 is rated Critical Active Threat (95.6/100): CVSS Critical severity, with high exploitation likelihood (EPSS 83.28%, 100th percentile). Core evidence: CISA KEV confirms active exploitation (added 2025-10-06) affecting Mozilla / Multiple Products. a weakness (CWE-119) Unauthenticated remote administrative access may be possible. Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
: Mozilla Multiple Products Remote Code Execution Vulnerability · CISA KEV detail
: 2025-10-06
: 2025-10-27
: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 16509 | exploit_db | edb | 2011-02-22 | Exploit-DB ↗ |
| 15352 | exploit_db | edb | 2010-10-29 | Exploit-DB ↗ |
| 15342 | exploit_db | edb | 2010-10-28 | Exploit-DB ↗ |
| 15341 | exploit_db | edb | 2010-10-28 | Exploit-DB ↗ |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 86.77% | 83.28% | -3.49% |
| 2 | 2026-05-17 | 86.62% | 86.77% | +0.15% |
| 3 | 2026-04-23 | — | 86.62% | — |
Full EPSS history (29 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| 9.3 | 2.0 | HIGH |
|
8.6 | 10.0 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
gentoo
|
high | CVE-2010-3765: 1 GLSA(s) (201301-01), 14 atom(s) (dev-libs/nss, mail-client/mozilla-thunderbird, …); latest impact high. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2010-3765 |
redhat
|
critical | — | https://access.redhat.com/security/cve/CVE-2010-3765 |
suse
|
critical | CVE-2010-3765 severity critical: SUSE including 117 source package names (MozillaFirefox-10.0-0.3.2, MozillaFirefox-140.2.0-160000.1.2, …), 184 product×package rows across 33 product lines (SUSE Linux Enterprise Desktop 12, SUSE Linux Enterprise Desktop 12 SP1, … (33 product lines)): Fixed 184. | https://www.suse.com/security/cve/CVE-2010-3765/ |
ubuntu
|
high | CVE-2010-3765 high priority: Ubuntu including 6 source packages (firefox, firefox-3.0, firefox-3.5, seamonkey, thunderbird, xulrunner-1.9.2), 36 status rows across 6 suites (dapper, hardy, karmic, lucid, maverick, upstream): released 20, DNE 12, ignored 2, needs-triage 2. | https://ubuntu.com/security/CVE-2010-3765 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| mozilla | firefox | 3.5 | cpe:2.3:a:mozilla:firefox:3.5:*:*:*:*:*:*:* |
| mozilla | firefox | 3.5.1 | cpe:2.3:a:mozilla:firefox:3.5.1:*:*:*:*:*:*:* |
| mozilla | firefox | 3.5.2 | cpe:2.3:a:mozilla:firefox:3.5.2:*:*:*:*:*:*:* |
| mozilla | firefox | 3.5.3 | cpe:2.3:a:mozilla:firefox:3.5.3:*:*:*:*:*:*:* |
| mozilla | firefox | 3.5.4 | cpe:2.3:a:mozilla:firefox:3.5.4:*:*:*:*:*:*:* |
| mozilla | firefox | 3.5.5 | cpe:2.3:a:mozilla:firefox:3.5.5:*:*:*:*:*:*:* |
| mozilla | firefox | 3.5.6 | cpe:2.3:a:mozilla:firefox:3.5.6:*:*:*:*:*:*:* |
| mozilla | firefox | 3.5.7 | cpe:2.3:a:mozilla:firefox:3.5.7:*:*:*:*:*:*:* |
| mozilla | firefox | 3.5.8 | cpe:2.3:a:mozilla:firefox:3.5.8:*:*:*:*:*:*:* |
| mozilla | firefox | 3.5.9 | cpe:2.3:a:mozilla:firefox:3.5.9:*:*:*:*:*:*:* |
| mozilla | firefox | 3.5.10 | cpe:2.3:a:mozilla:firefox:3.5.10:*:*:*:*:*:*:* |
| mozilla | firefox | 3.5.11 | cpe:2.3:a:mozilla:firefox:3.5.11:*:*:*:*:*:*:* |
| mozilla | firefox | 3.5.12 | cpe:2.3:a:mozilla:firefox:3.5.12:*:*:*:*:*:*:* |
| mozilla | firefox | 3.5.13 | cpe:2.3:a:mozilla:firefox:3.5.13:*:*:*:*:*:*:* |
| mozilla | firefox | 3.5.14 | cpe:2.3:a:mozilla:firefox:3.5.14:*:*:*:*:*:*:* |
| mozilla | firefox | 3.6 | cpe:2.3:a:mozilla:firefox:3.6:*:*:*:*:*:*:* |
| mozilla | firefox | 3.6.2 | cpe:2.3:a:mozilla:firefox:3.6.2:*:*:*:*:*:*:* |
| mozilla | firefox | 3.6.3 | cpe:2.3:a:mozilla:firefox:3.6.3:*:*:*:*:*:*:* |
| mozilla | firefox | 3.6.4 | cpe:2.3:a:mozilla:firefox:3.6.4:*:*:*:*:*:*:* |
| mozilla | firefox | 3.6.6 | cpe:2.3:a:mozilla:firefox:3.6.6:*:*:*:*:*:*:* |
| mozilla | firefox | 3.6.7 | cpe:2.3:a:mozilla:firefox:3.6.7:*:*:*:*:*:*:* |
| mozilla | firefox | 3.6.8 | cpe:2.3:a:mozilla:firefox:3.6.8:*:*:*:*:*:*:* |
| mozilla | firefox | 3.6.9 | cpe:2.3:a:mozilla:firefox:3.6.9:*:*:*:*:*:*:* |
| mozilla | firefox | 3.6.10 | cpe:2.3:a:mozilla:firefox:3.6.10:*:*:*:*:*:*:* |
| mozilla | firefox | 3.6.11 | cpe:2.3:a:mozilla:firefox:3.6.11:*:*:*:*:*:*:* |
| mozilla | thunderbird | 3.0.1 | cpe:2.3:a:mozilla:thunderbird:3.0.1:*:*:*:*:*:*:* |
| mozilla | thunderbird | 3.0.2 | cpe:2.3:a:mozilla:thunderbird:3.0.2:*:*:*:*:*:*:* |
| mozilla | thunderbird | 3.0.3 | cpe:2.3:a:mozilla:thunderbird:3.0.3:*:*:*:*:*:*:* |
| mozilla | thunderbird | 3.0.4 | cpe:2.3:a:mozilla:thunderbird:3.0.4:*:*:*:*:*:*:* |
| mozilla | thunderbird | 3.0.5 | cpe:2.3:a:mozilla:thunderbird:3.0.5:*:*:*:*:*:*:* |
| mozilla | thunderbird | 3.0.6 | cpe:2.3:a:mozilla:thunderbird:3.0.6:*:*:*:*:*:*:* |
| mozilla | thunderbird | 3.0.7 | cpe:2.3:a:mozilla:thunderbird:3.0.7:*:*:*:*:*:*:* |
| mozilla | thunderbird | 3.0.8 | cpe:2.3:a:mozilla:thunderbird:3.0.8:*:*:*:*:*:*:* |
| mozilla | thunderbird | 3.0.9 | cpe:2.3:a:mozilla:thunderbird:3.0.9:*:*:*:*:*:*:* |
| mozilla | thunderbird | 3.1.1 | cpe:2.3:a:mozilla:thunderbird:3.1.1:*:*:*:*:*:*:* |
| mozilla | thunderbird | 3.1.2 | cpe:2.3:a:mozilla:thunderbird:3.1.2:*:*:*:*:*:*:* |
| mozilla | thunderbird | 3.1.3 | cpe:2.3:a:mozilla:thunderbird:3.1.3:*:*:*:*:*:*:* |
| mozilla | thunderbird | 3.1.4 | cpe:2.3:a:mozilla:thunderbird:3.1.4:*:*:*:*:*:*:* |
| mozilla | thunderbird | 3.1.5 | cpe:2.3:a:mozilla:thunderbird:3.1.5:*:*:*:*:*:*:* |
| mozilla | seamonkey | 2.0 | cpe:2.3:a:mozilla:seamonkey:2.0:*:*:*:*:*:*:* |
| mozilla | seamonkey | 2.0 | cpe:2.3:a:mozilla:seamonkey:2.0:alpha_1:*:*:*:*:*:* |
| mozilla | seamonkey | 2.0 | cpe:2.3:a:mozilla:seamonkey:2.0:alpha_2:*:*:*:*:*:* |
| mozilla | seamonkey | 2.0 | cpe:2.3:a:mozilla:seamonkey:2.0:alpha_3:*:*:*:*:*:* |
| mozilla | seamonkey | 2.0 | cpe:2.3:a:mozilla:seamonkey:2.0:beta_1:*:*:*:*:*:* |
| mozilla | seamonkey | 2.0 | cpe:2.3:a:mozilla:seamonkey:2.0:beta_2:*:*:*:*:*:* |
| mozilla | seamonkey | 2.0 | cpe:2.3:a:mozilla:seamonkey:2.0:rc1:*:*:*:*:*:* |
| mozilla | seamonkey | 2.0 | cpe:2.3:a:mozilla:seamonkey:2.0:rc2:*:*:*:*:*:* |
| mozilla | seamonkey | 2.0.1 | cpe:2.3:a:mozilla:seamonkey:2.0.1:*:*:*:*:*:*:* |
| mozilla | seamonkey | 2.0.2 | cpe:2.3:a:mozilla:seamonkey:2.0.2:*:*:*:*:*:*:* |
| mozilla | seamonkey | 2.0.3 | cpe:2.3:a:mozilla:seamonkey:2.0.3:*:*:*:*:*:*:* |
| mozilla | seamonkey | 2.0.4 | cpe:2.3:a:mozilla:seamonkey:2.0.4:*:*:*:*:*:*:* |
| mozilla | seamonkey | 2.0.5 | cpe:2.3:a:mozilla:seamonkey:2.0.5:*:*:*:*:*:*:* |
| mozilla | seamonkey | 2.0.6 | cpe:2.3:a:mozilla:seamonkey:2.0.6:*:*:*:*:*:*:* |
| mozilla | seamonkey | 2.0.7 | cpe:2.3:a:mozilla:seamonkey:2.0.7:*:*:*:*:*:*:* |
| mozilla | seamonkey | 2.0.8 | cpe:2.3:a:mozilla:seamonkey:2.0.8:*:*:*:*:*:*:* |
| mozilla | seamonkey | 2.0.9 | cpe:2.3:a:mozilla:seamonkey:2.0.9:*:*:*:*:*:*:* |