Skip to content
COOEY

EXPOSURES › CVE-2010-3765

CVE-2010-3765

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-10-06 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2010-3765 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Mozilla Firefox, SeaMonkey, and Thunderbird exposed to remote code execution due to unpatched memory corruption issues.

Mozilla's Firefox, SeaMonkey, and Thunderbird browsers and email client suffered from unpatched memory corruption vulnerabilities, allowing remote attackers to execute arbitrary code. This highlights Mozilla's chronic pattern of critical security issues that expose users to remote code execution and privilege escalation.

Shame score — Chronic pattern of critical security issues leading to remote code execution and privilege escalation.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.