CVE-2010-3765Active Exploitation(mozilla / firefox)

LOWCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Prioritize remediation for mozilla firefox systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware.

3.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-10-27. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-119

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • firefox
  • seamonkey
  • thunderbird

Threat summary

  • Active exploitation appears in 2 classified signals
  • 3 mentions across 1 observed day

What's happening

  • Active exploitation reported across 2 signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
firefoxseamonkeythunderbird

49 versions affected across 3 products

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-01: 3Active Exploitation · 2026-05-01: 205-01
Signal classification2 categories
Active Exploitation
266.7%
General
133.3%
Referenced assets1 URL
Full discourse3 posts
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    Vendor. CISA added CVE-2010-3765 (Mozilla Multiple Products) to the Known Exploited Vulnerabilities catalog on 2025-10-06, signaling confirmed in-the-wild exploitation

    Post summary

    CISA added CVE-2010-3765 to its Known Exploited Vulnerabilities catalog, indicating confirmed in-the-wild exploitation of the vulnerability.

    1000015
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2010-3765. What happened CISA added CVE-2010-3765 (Mozilla Multiple Products) to the Known Exploited Vulnerabilities catalog on 2025-10-06, signaling confirmed in-the-wild exploitation CISA KEV.

    Post summary

    CISA has listed CVE‑2010‑3765 in its Known Exploited Vulnerabilities catalog, confirming it is currently being exploited in the wild.

    1000030
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://research.lyrie.ai/research/active-exploit-cve-2010-3765-multiple-products #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    A link to a research page is shared, but the text contains no explicit information about the vulnerability or its exploitation.

    0000027
    152 followersView on X
CPE platform detail56 entries

56 of 56 entries

PartVendorProductVersionTarget SWTarget HW
Appmozillafirefox3.5--
Appmozillafirefox3.5.1--
Appmozillafirefox3.5.10--
Appmozillafirefox3.5.11--
Appmozillafirefox3.5.12--
Appmozillafirefox3.5.13--
Appmozillafirefox3.5.14--
Appmozillafirefox3.5.2--
Appmozillafirefox3.5.3--
Appmozillafirefox3.5.4--
Appmozillafirefox3.5.5--
Appmozillafirefox3.5.6--
Appmozillafirefox3.5.7--
Appmozillafirefox3.5.8--
Appmozillafirefox3.5.9--
Appmozillafirefox3.6--
Appmozillafirefox3.6.10--
Appmozillafirefox3.6.11--
Appmozillafirefox3.6.2--
Appmozillafirefox3.6.3--
Appmozillafirefox3.6.4--
Appmozillafirefox3.6.6--
Appmozillafirefox3.6.7--
Appmozillafirefox3.6.8--
Appmozillafirefox3.6.9--
Appmozillaseamonkey2.0--
Appmozillaseamonkey2.0--
Appmozillaseamonkey2.0--
Appmozillaseamonkey2.0--
Appmozillaseamonkey2.0--
Appmozillaseamonkey2.0--
Appmozillaseamonkey2.0--
Appmozillaseamonkey2.0--
Appmozillaseamonkey2.0.1--
Appmozillaseamonkey2.0.2--
Appmozillaseamonkey2.0.3--
Appmozillaseamonkey2.0.4--
Appmozillaseamonkey2.0.5--
Appmozillaseamonkey2.0.6--
Appmozillaseamonkey2.0.7--
Appmozillaseamonkey2.0.8--
Appmozillaseamonkey2.0.9--
Appmozillathunderbird3.0.1--
Appmozillathunderbird3.0.2--
Appmozillathunderbird3.0.3--
Appmozillathunderbird3.0.4--
Appmozillathunderbird3.0.5--
Appmozillathunderbird3.0.6--
Appmozillathunderbird3.0.7--
Appmozillathunderbird3.0.8--
Appmozillathunderbird3.0.9--
Appmozillathunderbird3.1.1--
Appmozillathunderbird3.1.2--
Appmozillathunderbird3.1.3--
Appmozillathunderbird3.1.4--
Appmozillathunderbird3.1.5--

Explore more