CVE-2010-3765

Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
mozillafirefox
3.5
mozillafirefox
3.5.1
mozillafirefox
3.5.2
mozillafirefox
3.5.3
mozillafirefox
3.5.4
mozillafirefox
3.5.5
mozillafirefox
3.5.6
mozillafirefox
3.5.7
mozillafirefox
3.5.8
mozillafirefox
3.5.9
mozillafirefox
3.5.10
mozillafirefox
3.5.11
mozillafirefox
3.5.12
mozillafirefox
3.5.13
mozillafirefox
3.5.14
mozillafirefox
3.6
mozillafirefox
3.6.2
mozillafirefox
3.6.3
mozillafirefox
3.6.4
mozillafirefox
3.6.6
mozillafirefox
3.6.7
mozillafirefox
3.6.8
mozillafirefox
3.6.9
mozillafirefox
3.6.10
mozillafirefox
3.6.11
mozillathunderbird
3.0.1
mozillathunderbird
3.0.2
mozillathunderbird
3.0.3
mozillathunderbird
3.0.4
mozillathunderbird
3.0.5
mozillathunderbird
3.0.6
mozillathunderbird
3.0.7
mozillathunderbird
3.0.8
mozillathunderbird
3.0.9
mozillathunderbird
3.1.1
mozillathunderbird
3.1.2
mozillathunderbird
3.1.3
mozillathunderbird
3.1.4
mozillathunderbird
3.1.5
mozillaseamonkey
2.0
mozillaseamonkey
2.0:alpha_1
mozillaseamonkey
2.0:alpha_2
mozillaseamonkey
2.0:alpha_3
mozillaseamonkey
2.0:beta_1
mozillaseamonkey
2.0:beta_2
mozillaseamonkey
2.0:rc1
mozillaseamonkey
2.0:rc2
mozillaseamonkey
2.0.1
mozillaseamonkey
2.0.2
mozillaseamonkey
2.0.3
mozillaseamonkey
2.0.4
mozillaseamonkey
2.0.5
mozillaseamonkey
2.0.6
mozillaseamonkey
2.0.7
mozillaseamonkey
2.0.8
mozillaseamonkey
2.0.9
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
maverick
Fixed 3.6.12+build1+nobinonly-0ubuntu0.10.10.1
released
lucid
Fixed 3.6.12+build1+nobinonly-0ubuntu0.10.04.1
released
karmic
dne
hardy
ignored
dapper
ignored
firefox-3.0
maverick
dne
lucid
dne
karmic
dne
hardy
Fixed 3.6.12+build1+nobinonly-0ubuntu0.8.04.1
released
dapper
dne
firefox-3.5
maverick
dne
lucid
dne
karmic
Fixed 3.6.12+build1+nobinonly-0ubuntu0.9.10.1
released
hardy
dne
dapper
dne
seamonkey
maverick
Fixed 2.0.10+build1+nobinonly-0ubuntu0.10.10.1
released
lucid
Fixed 2.0.10+build1+nobinonly-0ubuntu0.10.04.1
released
karmic
Fixed 2.0.10+build1+nobinonly-0ubuntu0.9.10.1
released
hardy
Fixed 2.0.10+build1+nobinonly-0ubuntu0.8.04.1
released
dapper
dne
thunderbird
maverick
Fixed 3.1.6+build1+nobinonly-0ubuntu0.10.10.1
released
lucid
Fixed 3.0.10+build1+nobinonly-0ubuntu0.10.04.1
released
karmic
Fixed 2.0.0.24+build1+nobinonly-0ubuntu0.9.10.3
released
hardy
Fixed 2.0.0.24+build1+nobinonly-0ubuntu0.8.04.2
released
dapper
dne
xulrunner-1.9.2
maverick
Fixed 1.9.2.12+build1+nobinonly-0ubuntu0.10.10.1
released
lucid
Fixed 1.9.2.12+build1+nobinonly-0ubuntu0.10.04.1
released
karmic
Fixed 1.9.2.12+build1+nobinonly-0ubuntu0.9.10.1
released
hardy
Fixed 1.9.2.12+build1+nobinonly-0ubuntu0.8.04.1
released
dapper
dne
References