CVE-2010-3765
KEVmassMemory Corruption RCE in Mozilla Firefox, SeaMonkey, and Thunderbird
CISA: Mozilla Multiple Products Remote Code Execution Vulnerability
Mozilla Firefox, SeaMonkey, and Thunderbird contain a memory-corruption vulnerability in the layout engine's CSS frame construction code (nsCSSFrameConstructor::ContentAppended) that is reachable whenever JavaScript is enabled. A remote attacker triggers the flaw by getting a user to load content — typically a malicious web page, or remote HTML content in Thunderbird — that calls the DOM appendChild method in a way that causes incorrect index tracking and the creation of multiple frames, corrupting memory. Successful exploitation allows the attacker to execute arbitrary code in the context of the affected application and the logged-in user. Anyone running the affected 2010-era Mozilla products with JavaScript enabled is exposed, which historically included the very large install base of these desktop applications. CISA added CVE-2010-3765 to its Known Exploited Vulnerabilities catalog on 2025-10-06, confirming exploitation in the wild (ransomware use not yet reported), and EPSS assigns an 83.3% probability of exploitation within the next 30 days.
What to do: Upgrade Firefox, SeaMonkey, and Thunderbird to the fixed releases specified in Mozilla's security advisory for CVE-2010-3765; as an interim measure, disable JavaScript in Firefox/SeaMonkey and block remote content in Thunderbird, since the flaw requires JavaScript to be enabled. Per the CISA KEV required action, apply vendor mitigations, follow applicable BOD 22-01 guidance, or discontinue use of the product if mitigations are unavailable — inventory for legacy Mozilla installations and prioritize remediation given the 83.3% EPSS score and confirmed in-the-wild exploitation.
| Mozilla Firefox | — |
| Mozilla SeaMonkey | — |
| Mozilla Thunderbird | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption.
- Affected
- Mozilla Multiple Products
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- Mozilla
- Products
- Multiple Products