CVE-2010-3765
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware.
- Affected products
- Firefox, Red Hat, Seamonkey, Suse, Thunderbird
- Mozilla Firefox
- = 3.5, 3.5.1, 3.5.2, 3.5.3, 3.5.4, 3.5.5, 3.5.6, 3.5.7, 3.5.8, 3.5.9, 3.5.10, 3.5.11, 3.5.12, 3.5.13, 3.5.14
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 83.3% (100th percentile)
- Weakness
- CWE-119
- NVD status
- Analyzed
- Published
- 2010-10-27
CVE-2010-3765 at NVD
17 known exploits for CVE-2010-3765
Proof-of-concept code and exploit modules indexed by Sploitus
Mozilla Firefox - Interleaving 'document.write' / 'appendChild' (Metasploit)
Mozilla Firefox Interleaving document.write / appendChild Code Execution
Mozilla Firefox document.write and DOM insertion memory corruption
Mozilla Firefox document.write and DOM insertion memory corruption
Mozilla Firefox document.write and DOM insertion memory corruption
Mozilla Firefox document.write and DOM insertion memory corruption
Mozilla Firefox document.write()方式堆溢出漏洞
Firefox Memory Corruption Proof of Concept (Simplified)
Firefox Memory Corruption Proof of Concept (Simplified)
Mozilla Firefox 3.6.8 < 3.6.11 - Interleaving 'document.write' / 'appendChild' Remote Overflow
Firefox Memory Corruption
Immunity Canvas: FIREFOX_APPENDCHILD
Mozilla Firefox - Simplified Memory Corruption (PoC)
Mozilla Firefox - Simplified Memory Corruption (PoC)
Mozilla Firefox - Interleaving 'document.write' / 'appendChild' Denial of Service
Firefox Interleaving Denial Of Service
Mozilla Firefox Interleaved document.write/appendChild Memory Corruption