Mozilla Multiple Products Remote Code Execution Vulnerability

Release Date: 06th of October 2025

Impact : HIGH / CRITICAL

TLP Rating: Clear

The Department of Communication and Digital Transformation (DCDT through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above products. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2010-3765 is a remote code execution vulnerability in Mozilla products (Firefox / SeaMonkey / Thunderbird) caused by a heap buffer overflow when mixing document.write and DOM insertion; it was actively exploited in October–November 2010.

 

References

  1. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  2. https://www.cve.org/CVERecord?id=CVE-2010-3765
  3. https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Exploit:JS/CVE-2010-3765