ZeroHour

CVE-2010-3765

KEVmass

Memory Corruption RCE in Mozilla Firefox, SeaMonkey, and Thunderbird

CISA: Mozilla Multiple Products Remote Code Execution Vulnerability

CVSS
EPSS
83%p100
Published
KEV added
AI analysis

Mozilla Firefox, SeaMonkey, and Thunderbird contain a memory-corruption vulnerability in the layout engine's CSS frame construction code (nsCSSFrameConstructor::ContentAppended) that is reachable whenever JavaScript is enabled. A remote attacker triggers the flaw by getting a user to load content — typically a malicious web page, or remote HTML content in Thunderbird — that calls the DOM appendChild method in a way that causes incorrect index tracking and the creation of multiple frames, corrupting memory. Successful exploitation allows the attacker to execute arbitrary code in the context of the affected application and the logged-in user. Anyone running the affected 2010-era Mozilla products with JavaScript enabled is exposed, which historically included the very large install base of these desktop applications. CISA added CVE-2010-3765 to its Known Exploited Vulnerabilities catalog on 2025-10-06, confirming exploitation in the wild (ransomware use not yet reported), and EPSS assigns an 83.3% probability of exploitation within the next 30 days.

What to do: Upgrade Firefox, SeaMonkey, and Thunderbird to the fixed releases specified in Mozilla's security advisory for CVE-2010-3765; as an interim measure, disable JavaScript in Firefox/SeaMonkey and block remote content in Thunderbird, since the flaw requires JavaScript to be enabled. Per the CISA KEV required action, apply vendor mitigations, follow applicable BOD 22-01 guidance, or discontinue use of the product if mitigations are unavailable — inventory for legacy Mozilla installations and prioritize remediation given the 83.3% EPSS score and confirmed in-the-wild exploitation.

Affected
Mozilla Firefox
Mozilla SeaMonkey
Mozilla Thunderbird
Estimated exposure
massHundreds of millions of users (global Firefox/Thunderbird/SeaMonkey install base; chiefly unpatched legacy deployments today) — Mozilla Firefox ranked among the top desktop browsers with roughly a quarter to a third of global usage share in the era of this flaw, implying an install base in the hundreds of millions, with Thunderbird and SeaMonkey adding tens of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption.

CISA Known Exploited Vulnerability
Affected
Mozilla Multiple Products
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
Mozilla
Products
Multiple Products

In the news