AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2010-3768

HIGH · CVSS 9.3 EPSS 4.81%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2010-12-10 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2010-3768
Severity
HIGH
CVSS
9.3
EPSS
4.81%
Firefox

Original Filing — NVD Description

Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 do not properly validate downloadable fonts before use within an operating system's font implementation, which allows remote attackers to execute arbitrary code via vectors related to @font-face Cascading Style Sheets (CSS) rules.