Куда я попал?
SECURITM это SGRC система, ? автоматизирующая процессы в службах информационной безопасности. SECURITM помогает построить и управлять ИСПДн, КИИ, ГИС, СМИБ/СУИБ, банковскими системами защиты.
А еще SECURITM это место для обмена опытом и наработками для служб безопасности.

CVE-2010-3765

PUBLISHED 22.10.2025

CNA: mitre

Обновлено: 18.09.2017
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware.

EPSS

Вероятность Severity Процентиль ? Дата расчёта
86.77% CRITICAL 99.44 23.05.2026

Exploits & Shellcodes

Идентификатор Тип Описание Дата публикации
EDB-16509 Exploit Mozilla Firefox - Interleaving 'document.write' / 'appendChild' (Metasploit) 22.02.2011
EDB-15352 Exploit Mozilla Firefox 3.6.8 < 3.6.11 - Interleaving 'document.write' / 'appendChild' Remote Overflow 29.10.2010
EDB-15342 Exploit Mozilla Firefox - Simplified Memory Corruption (PoC) 28.10.2010
EDB-15341 Exploit Mozilla Firefox - Interleaving 'document.write' / 'appendChild' Denial of Service 28.10.2010

Доп. Информация

Product Status

n/a
Product: n/a
Vendor: n/a
Default status: Не определен
Версии:
Затронутые версии Статус
Наблюдалось в версии n/a affected
 

Ссылки

http://www.securityfocus.com/bid/44425
https://rhn.redhat.com/errata/RHSA-2010-0812.html
https://bugzilla.mozilla.org/show_bug.cgi?id=607222#c53
http://www.vupen.com/english/advisories/2010/2837
https://bugzilla.redhat.com/show_bug.cgi?id=646997
http://support.avaya.com/css/P8/documents/100114335
http://secunia.com/advisories/41965
http://secunia.com/advisories/41975
http://www.redhat.com/support/errata/RHSA-2010-0896.html
http://www.redhat.com/support/errata/RHSA-2010-0808.html
http://www.exploit-db.com/exploits/15341
http://www.securitytracker.com/id?1024651
http://secunia.com/advisories/41761
https://bugzilla.mozilla.org/show_bug.cgi?id=607222
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050233.html
http://norman.com/about_norman/press_center/news_archive/2010/129223/en?utm_source=twitterfeed&utm_medium=twitter
http://secunia.com/advisories/41969
http://www.ubuntu.com/usn/USN-1011-3
http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozilla_firefox
http://www.norman.com/about_norman/press_center/news_archive/2010/129223/
http://www.ubuntu.com/usn/usn-1011-1
http://www.securitytracker.com/id?1024650
http://www.ubuntu.com/usn/USN-1011-2
http://www.redhat.com/support/errata/RHSA-2010-0809.html
http://www.mandriva.com/security/advisories?name=MDVSA-2010:219
http://secunia.com/advisories/42867
http://blog.mozilla.com/security/2010/10/26/critical-vulnerability-in-firefox-3-5-and-firefox-3-6/
http://www.vupen.com/english/advisories/2010/2857
http://www.vupen.com/english/advisories/2011/0061
http://support.avaya.com/css/P8/documents/100114329
http://www.debian.org/security/2010/dsa-2124
http://www.securitytracker.com/id?1024645
http://secunia.com/advisories/42043
http://www.norman.com/security_center/virus_description_archive/129146/
http://secunia.com/advisories/41966
http://www.mandriva.com/security/advisories?name=MDVSA-2010:213
http://secunia.com/advisories/42008
http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050061.html
http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.556706
http://www.vupen.com/english/advisories/2010/2871
http://isc.sans.edu/diary.html?storyid=9817
http://www.redhat.com/support/errata/RHSA-2010-0810.html
http://www.mozilla.org/security/announce/2010/mfsa2010-73.html
http://www.exploit-db.com/exploits/15352
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12108
http://secunia.com/advisories/42003
http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050077.html
http://www.redhat.com/support/errata/RHSA-2010-0861.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050154.html
http://www.exploit-db.com/exploits/15342
http://www.vupen.com/english/advisories/2010/2864

CVE Program Container

Обновлено: 07.08.2024
SSVC and KEV, plus CVSS and CWE if not provided by the CNA.

Ссылки

http://www.securityfocus.com/bid/44425
https://rhn.redhat.com/errata/RHSA-2010-0812.html
https://bugzilla.mozilla.org/show_bug.cgi?id=607222#c53
http://www.vupen.com/english/advisories/2010/2837
https://bugzilla.redhat.com/show_bug.cgi?id=646997
http://support.avaya.com/css/P8/documents/100114335
http://secunia.com/advisories/41965
http://secunia.com/advisories/41975
http://www.redhat.com/support/errata/RHSA-2010-0896.html
http://www.redhat.com/support/errata/RHSA-2010-0808.html
http://www.exploit-db.com/exploits/15341
http://www.securitytracker.com/id?1024651
http://secunia.com/advisories/41761
https://bugzilla.mozilla.org/show_bug.cgi?id=607222
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050233.html
http://norman.com/about_norman/press_center/news_archive/2010/129223/en?utm_source=twitterfeed&utm_medium=twitter
http://secunia.com/advisories/41969
http://www.ubuntu.com/usn/USN-1011-3
http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozilla_firefox
http://www.norman.com/about_norman/press_center/news_archive/2010/129223/
http://www.ubuntu.com/usn/usn-1011-1
http://www.securitytracker.com/id?1024650
http://www.ubuntu.com/usn/USN-1011-2
http://www.redhat.com/support/errata/RHSA-2010-0809.html
http://www.mandriva.com/security/advisories?name=MDVSA-2010:219
http://secunia.com/advisories/42867
http://blog.mozilla.com/security/2010/10/26/critical-vulnerability-in-firefox-3-5-and-firefox-3-6/
http://www.vupen.com/english/advisories/2010/2857
http://www.vupen.com/english/advisories/2011/0061
http://support.avaya.com/css/P8/documents/100114329
http://www.debian.org/security/2010/dsa-2124
http://www.securitytracker.com/id?1024645
http://secunia.com/advisories/42043
http://www.norman.com/security_center/virus_description_archive/129146/
http://secunia.com/advisories/41966
http://www.mandriva.com/security/advisories?name=MDVSA-2010:213
http://secunia.com/advisories/42008
http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050061.html
http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.556706
http://www.vupen.com/english/advisories/2010/2871
http://isc.sans.edu/diary.html?storyid=9817
http://www.redhat.com/support/errata/RHSA-2010-0810.html
http://www.mozilla.org/security/announce/2010/mfsa2010-73.html
http://www.exploit-db.com/exploits/15352
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12108
http://secunia.com/advisories/42003
http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050077.html
http://www.redhat.com/support/errata/RHSA-2010-0861.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050154.html
http://www.exploit-db.com/exploits/15342
http://www.vupen.com/english/advisories/2010/2864

CISA ADP Vulnrichment

Обновлено: 22.10.2025
Этот блок содержит дополнительную информацию, предоставленную программой CVE для этой уязвимости.

CVSS

Оценка Severity Версия Базовый вектор
9.8 CRITICAL 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

SSVC

Exploitation Automatable Technical Impact Версия Дата доступа
active yes total 2.0.3 04.10.2025

Ссылки

Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.