⚠ Actively exploited
Added to CISA KEV on 2025-10-06. Federal agencies required to patch by 2025-10-27. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable..

CVE-2010-3765Improper Restriction of Operations within the Bounds of a Memory Buffer in Mozilla Firefox

Severity
9.8CRITICALNVD
EPSS
87.2%
top 0.55%
CISA KEV
KEV
Added 2025-10-06
Due 2025-10-27
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedOct 28
KEV addedOct 6
KEV dueOct 27
CISA Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Description

Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

NVDmozilla/firefox25 versions+24
NVDmozilla/seamonkey10 versions+9
NVDmozilla/thunderbird14 versions+13

🔴Vulnerability Details

3
GHSA
GHSA-cmrc-q43h-xrrq: Mozilla Firefox 32022-05-17
CVEList
CVE-2010-3765: Mozilla Firefox 32010-10-27
VulnCheck
Mozilla Multiple Products Remote Code Execution Vulnerability2010

💥Exploits & PoCs

5
Exploit-DB
Mozilla Firefox - Interleaving 'document.write' / 'appendChild' (Metasploit)2011-02-22
Exploit-DB
Mozilla Firefox 3.6.8 < 3.6.11 - Interleaving 'document.write' / 'appendChild' Remote Overflow2010-10-29
Exploit-DB
Mozilla Firefox - Interleaving 'document.write' / 'appendChild' Denial of Service2010-10-28
Exploit-DB
Mozilla Firefox - Simplified Memory Corruption (PoC)2010-10-28
Metasploit
Mozilla Firefox Interleaved document.write/appendChild Memory Corruption

📋Vendor Advisories

5
CISA
Mozilla Multiple Products Remote Code Execution Vulnerability2025-10-06
Ubuntu
Xulrunner vulnerability2010-10-29
Ubuntu
Thunderbird vulnerability2010-10-28
Ubuntu
Firefox vulnerability2010-10-28
Red Hat
Firefox race condition flaw (MFSA 2010-73)2010-10-28

🕵️Threat Intelligence

1
Recorded Future
October 2025 CVE Landscape

💬Community

1
Bugzilla
CVE-2010-3765 Firefox race condition flaw (MFSA 2010-73)2010-10-26
CVE-2010-3765 — Mozilla Firefox vulnerability | cvebase