CVE-2010-3765
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Mozilla Multiple Products Remote Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 83% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-119
מוצרים מושפעים
mozilla: firefox; mozilla: thunderbird; mozilla: seamonkey
קישורים
- http://blog.mozilla.com/security/2010/10/26/critical-vulnerability-in-firefox-… Vendor Advisory
- http://secunia.com/advisories/41761 Vendor Advisory
- http://secunia.com/advisories/41965 Vendor Advisory
- http://secunia.com/advisories/41966 Vendor Advisory
- http://secunia.com/advisories/41969 Vendor Advisory
- http://secunia.com/advisories/41975 Vendor Advisory
- http://secunia.com/advisories/42003 Vendor Advisory
- http://secunia.com/advisories/42008 Vendor Advisory
- http://secunia.com/advisories/42043 Vendor Advisory
- http://secunia.com/advisories/42867 Vendor Advisory