Back

CRITICAL KEV

Firefox race condition flaw (MFSA 2010-73)

Published Oct 27, 2010 ·Due Oct 27, 2025

Description

Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (56)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 27, 2010
Updated Oct 22, 2025
Reserved Oct 5, 2010
CISA Vulnrichment
Updated Oct 4, 2025
NVD
Status Analyzed
Modified Jun 16, 2026
Red Hat
Severity Critical
Public date Oct 28, 2010