CVE-2010-3765

EUVD-2010-3744
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
Affected Products (NVD)
VendorProductVersion
mozillafirefox
3.5
mozillafirefox
3.5.1
mozillafirefox
3.5.2
mozillafirefox
3.5.3
mozillafirefox
3.5.4
mozillafirefox
3.5.5
mozillafirefox
3.5.6
mozillafirefox
3.5.7
mozillafirefox
3.5.8
mozillafirefox
3.5.9
mozillafirefox
3.5.10
mozillafirefox
3.5.11
mozillafirefox
3.5.12
mozillafirefox
3.5.13
mozillafirefox
3.5.14
mozillafirefox
3.6
mozillafirefox
3.6.2
mozillafirefox
3.6.3
mozillafirefox
3.6.4
mozillafirefox
3.6.6
mozillafirefox
3.6.7
mozillafirefox
3.6.8
mozillafirefox
3.6.9
mozillafirefox
3.6.10
mozillafirefox
3.6.11
mozillathunderbird
3.0.1
mozillathunderbird
3.0.2
mozillathunderbird
3.0.3
mozillathunderbird
3.0.4
mozillathunderbird
3.0.5
mozillathunderbird
3.0.6
mozillathunderbird
3.0.7
mozillathunderbird
3.0.8
mozillathunderbird
3.0.9
mozillathunderbird
3.1.1
mozillathunderbird
3.1.2
mozillathunderbird
3.1.3
mozillathunderbird
3.1.4
mozillathunderbird
3.1.5
mozillaseamonkey
2.0
mozillaseamonkey
2.0:alpha_1
mozillaseamonkey
2.0:alpha_2
mozillaseamonkey
2.0:alpha_3
mozillaseamonkey
2.0:beta_1
mozillaseamonkey
2.0:beta_2
mozillaseamonkey
2.0:rc1
mozillaseamonkey
2.0:rc2
mozillaseamonkey
2.0.1
mozillaseamonkey
2.0.2
mozillaseamonkey
2.0.3
mozillaseamonkey
2.0.4
mozillaseamonkey
2.0.5
mozillaseamonkey
2.0.6
mozillaseamonkey
2.0.7
mozillaseamonkey
2.0.8
mozillaseamonkey
2.0.9
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
dapper
ignored
hardy
ignored
karmic
dne
lucid
Fixed 3.6.12+build1+nobinonly-0ubuntu0.10.04.1
released
maverick
Fixed 3.6.12+build1+nobinonly-0ubuntu0.10.10.1
released
firefox-3.0
dapper
dne
hardy
Fixed 3.6.12+build1+nobinonly-0ubuntu0.8.04.1
released
karmic
dne
lucid
dne
maverick
dne
firefox-3.5
dapper
dne
hardy
dne
karmic
Fixed 3.6.12+build1+nobinonly-0ubuntu0.9.10.1
released
lucid
dne
maverick
dne
seamonkey
dapper
dne
hardy
Fixed 2.0.10+build1+nobinonly-0ubuntu0.8.04.1
released
karmic
Fixed 2.0.10+build1+nobinonly-0ubuntu0.9.10.1
released
lucid
Fixed 2.0.10+build1+nobinonly-0ubuntu0.10.04.1
released
maverick
Fixed 2.0.10+build1+nobinonly-0ubuntu0.10.10.1
released
thunderbird
dapper
dne
hardy
Fixed 2.0.0.24+build1+nobinonly-0ubuntu0.8.04.2
released
karmic
Fixed 2.0.0.24+build1+nobinonly-0ubuntu0.9.10.3
released
lucid
Fixed 3.0.10+build1+nobinonly-0ubuntu0.10.04.1
released
maverick
Fixed 3.1.6+build1+nobinonly-0ubuntu0.10.10.1
released
xulrunner-1.9.2
dapper
dne
hardy
Fixed 1.9.2.12+build1+nobinonly-0ubuntu0.8.04.1
released
karmic
Fixed 1.9.2.12+build1+nobinonly-0ubuntu0.9.10.1
released
lucid
Fixed 1.9.2.12+build1+nobinonly-0ubuntu0.10.04.1
released
maverick
Fixed 1.9.2.12+build1+nobinonly-0ubuntu0.10.10.1
released
References