Firefox race condition flaw (MFSA 2010-73)
Published Oct 27, 2010 ·Due Oct 27, 2025
9.8
CRITICALCVSS 3.1
EPSS 83.16%
Description
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware.
Affected products
No data.
Configuration 1
- 3.5
- 3.5.1
- 3.5.2
- 3.5.3
- 3.5.4
- 3.5.5
- 3.5.6
- 3.5.7
- 3.5.8
- 3.5.9
- 3.5.10
- 3.5.11
- 3.5.12
- 3.5.13
- 3.5.14
Configuration 2
- 3.6
- 3.6.2
- 3.6.3
- 3.6.4
- 3.6.6
- 3.6.7
- 3.6.8
- 3.6.9
- 3.6.10
- 3.6.11
Configuration 3
- 3.0.1
- 3.0.2
- 3.0.3
- 3.0.4
- 3.0.5
- 3.0.6
- 3.0.7
- 3.0.8
- 3.0.9
- 3.1.1
- 3.1.2
- 3.1.3
- 3.1.4
- 3.1.5
Configuration 4
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0.1
- 2.0.2
- 2.0.3
- 2.0.4
- 2.0.5
- 2.0.6
- 2.0.7
- 2.0.8
- 2.0.9
No data.
Red Hat Enterprise Linux 3
seamonkey-0:1.0.9-0.62.el3
Fixed · RHSA-2010:0810
Red Hat Enterprise Linux 4
firefox-0:3.6.11-4.el4_8
Fixed · RHSA-2010:0808
Red Hat Enterprise Linux 4
seamonkey-0:1.0.9-65.el4_8
Fixed · RHSA-2010:0810
Red Hat Enterprise Linux 4
thunderbird-0:1.5.0.12-33.el4
Fixed · RHSA-2010:0812
Red Hat Enterprise Linux 5
thunderbird-0:2.0.0.24-10.el5_5
Fixed · RHSA-2010:0812
Red Hat Enterprise Linux 5
xulrunner-0:1.9.2.11-4.el5_5
Fixed · RHSA-2010:0809
Red Hat Enterprise Linux 6
firefox-0:3.6.12-1.el6_0
Fixed · RHSA-2010:0861
Red Hat Enterprise Linux 6
thunderbird-0:3.1.6-1.el6_0
Fixed · RHSA-2010:0896
Red Hat Enterprise Linux 6
xulrunner-0:1.9.2.12-1.el6_0
Fixed · RHSA-2010:0861
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | seamonkey-0:1.0.9-0.62.el3 | Fixed | RHSA-2010:0810 |
| Red Hat Enterprise Linux 4 | firefox-0:3.6.11-4.el4_8 | Fixed | RHSA-2010:0808 |
| Red Hat Enterprise Linux 4 | seamonkey-0:1.0.9-65.el4_8 | Fixed | RHSA-2010:0810 |
| Red Hat Enterprise Linux 4 | thunderbird-0:1.5.0.12-33.el4 | Fixed | RHSA-2010:0812 |
| Red Hat Enterprise Linux 5 | thunderbird-0:2.0.0.24-10.el5_5 | Fixed | RHSA-2010:0812 |
| Red Hat Enterprise Linux 5 | xulrunner-0:1.9.2.11-4.el5_5 | Fixed | RHSA-2010:0809 |
| Red Hat Enterprise Linux 6 | firefox-0:3.6.12-1.el6_0 | Fixed | RHSA-2010:0861 |
| Red Hat Enterprise Linux 6 | thunderbird-0:3.1.6-1.el6_0 | Fixed | RHSA-2010:0896 |
| Red Hat Enterprise Linux 6 | xulrunner-0:1.9.2.12-1.el6_0 | Fixed | RHSA-2010:0861 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Date Added
Oct 6, 2025
Patch Due
Oct 27, 2025
Required Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Oct 4, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (20 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 83.16% (0.83156) | 99.67th | v5 (v2026.06.15) |
| Jun 15, 2026 | 83.28% (0.83279) | 99.64th | v5 (v2026.06.15) |
| Apr 12, 2026 | 87.24% (0.87242) | 99.45th | v4 (v2025.03.14) |
| Mar 10, 2026 | 86.02% (0.86015) | 99.38th | v4 (v2025.03.14) |
| Mar 30, 2025 | 87.77% (0.87771) | 99.44th | v4 (v2025.03.14) |
| Mar 29, 2025 | 89.58% (0.89583) | 99.47th | v4 (v2025.03.14) |
| Mar 17, 2025 | 87.35% (0.87350) | 99.41th | v4 (v2025.03.14) |
| Dec 17, 2024 | 94.11% (0.94110) | 99.38th | v3 (v2023.03.01) |
| Dec 12, 2024 | 97.00% (0.96995) | 99.80th | v3 (v2023.03.01) |
| Jun 19, 2024 | 96.73% (0.96733) | 99.67th | v3 (v2023.03.01) |
| Mar 24, 2024 | 97.09% (0.97089) | 99.76th | v3 (v2023.03.01) |
| Feb 10, 2024 | 97.03% (0.97027) | 99.72th | v3 (v2023.03.01) |
| Nov 13, 2023 | 97.06% (0.97062) | 99.70th | v3 (v2023.03.01) |
| Sep 25, 2023 | 97.13% (0.97133) | 99.71th | v3 (v2023.03.01) |
| Aug 6, 2023 | 96.97% (0.96975) | 99.61th | v3 (v2023.03.01) |
| Jun 17, 2023 | 96.97% (0.96966) | 99.58th | v3 (v2023.03.01) |
| Apr 27, 2023 | 96.81% (0.96807) | 99.46th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.02% (0.97020) | 99.53th | v3 (v2023.03.01) |
| Mar 6, 2023 | 83.36% (0.83364) | 99.60th | v2 (v2022.01.01) |
| Feb 4, 2022 | 83.36% (0.83364) | 99.52th | v2 (v2022.01.01) |
References (56)
- http://blog.mozilla.com/security/2010/10/26/critical-vulnerability-in-firefox-3-5-and-firefox-3-6/ x_refsource_CONFIRMVendor Advisory
- http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozilla_firefox x_refsource_CONFIRMBroken Link
- http://isc.sans.edu/diary.html?storyid=9817 x_refsource_MISCPress/Media Coverage
- http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050233.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050061.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050077.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2010-October/050154.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
- http://norman.com/about_norman/press_center/news_archive/2010/129223/en?utm_source=twitterfeed&utm_medium=twitter x_refsource_MISCProduct
- http://secunia.com/advisories/41761 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/41965 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/41966 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/41969 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/41975 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/42003 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/42008 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/42043 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/42867 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.556706 vendor-advisoryx_refsource_SLACKWAREThird Party Advisory
- http://support.avaya.com/css/P8/documents/100114329 x_refsource_CONFIRMThird Party Advisory
- http://support.avaya.com/css/P8/documents/100114335 x_refsource_CONFIRMThird Party Advisory
- http://www.debian.org/security/2010/dsa-2124 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.exploit-db.com/exploits/15341 exploitx_refsource_EXPLOIT-DB
- http://www.exploit-db.com/exploits/15342 exploitx_refsource_EXPLOIT-DB
- http://www.exploit-db.com/exploits/15352 exploitx_refsource_EXPLOIT-DB
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:213 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:219 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.mozilla.org/security/announce/2010/mfsa2010-73.html x_refsource_CONFIRMThird Party Advisory
- http://www.norman.com/about_norman/press_center/news_archive/2010/129223/ x_refsource_MISCBroken Link
- http://www.norman.com/security_center/virus_description_archive/129146/ x_refsource_MISCBroken Link
- http://www.redhat.com/support/errata/RHSA-2010-0808.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0809.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0810.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0861.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0896.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.securityfocus.com/bid/44425 vdb-entryx_refsource_BIDBroken Link
- http://www.securitytracker.com/id?1024645 vdb-entryx_refsource_SECTRACKBroken Link
- http://www.securitytracker.com/id?1024650 vdb-entryx_refsource_SECTRACKBroken Link
- http://www.securitytracker.com/id?1024651 vdb-entryx_refsource_SECTRACKBroken Link
- http://www.ubuntu.com/usn/USN-1011-2 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/USN-1011-3 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/usn-1011-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.vupen.com/english/advisories/2010/2837 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2010/2857 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2010/2864 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2010/2871 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2011/0061 vdb-entryx_refsource_VUPENVendor Advisory
- https://access.redhat.com/security/cve/CVE-2010-3765 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=607222 x_refsource_CONFIRMIssue Tracking
- https://bugzilla.mozilla.org/show_bug.cgi?id=607222#c53 x_refsource_MISCIssue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=646997 x_refsource_CONFIRMIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2010-3765
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12108 vdb-entrysignaturex_refsource_OVALThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2010-0812.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-3765 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2010-3765
Change history (0)
No recorded changes yet.