---
title: "CVE-2010-3776\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2010-3776?format=md
keywords: index, follow
---

# CVE-2010-3776

Publication date 9 December 2010

Last updated 26 May 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Multiple unspecified vulnerabilities in the browser engine in Mozilla
Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11
and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 allow remote attackers
to cause a denial of service (memory corruption and application crash) or
possibly execute arbitrary code via unknown vectors.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2010-3776?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| firefox | 11.04 natty | Fixed 4.0~b8+nobinonly-0ubuntu3 |
| 10.10 maverick | Fixed 3.6.13+build3+nobinonly-0ubuntu0.10.10.1 |
| 10.04 LTS lucid | Fixed 3.6.13+build3+nobinonly-0ubuntu0.10.04.1 |
| 9.10 karmic | Not in release |
| 8.04 LTS hardy | Ignored end of life |
| 6.06 LTS dapper | Ignored end of life |
| firefox-3.0 | 11.04 natty | Not in release |
| 10.10 maverick | Not in release |
| 10.04 LTS lucid | Not in release |
| 9.10 karmic | Not in release |
| 8.04 LTS hardy | Fixed 3.6.13+build3+nobinonly-0ubuntu0.8.04.1 |
| 6.06 LTS dapper | Not in release |
| firefox-3.5 | 11.04 natty | Not in release |
| 10.10 maverick | Not in release |
| 10.04 LTS lucid | Not in release |
| 9.10 karmic | Fixed 3.6.13+build3+nobinonly-0ubuntu0.9.10.1 |
| 8.04 LTS hardy | Not in release |
| 6.06 LTS dapper | Not in release |
| seamonkey | 11.04 natty | Fixed 2.0.11+build1+nobinonly-0ubuntu1 |
| 10.10 maverick | Fixed 2.0.11+build1+nobinonly-0ubuntu0.10.10.1 |
| 10.04 LTS lucid | Fixed 2.0.11+build1+nobinonly-0ubuntu0.10.04.1 |
| 9.10 karmic | Fixed 2.0.11+build1+nobinonly-0ubuntu0.9.10.1 |
| 8.04 LTS hardy | Fixed 2.0.11+build1+nobinonly-0ubuntu0.8.04.1 |
| 6.06 LTS dapper | Not in release |
| thunderbird | 11.04 natty | Fixed 3.1.7+build3+nobinonly-0ubuntu2 |
| 10.10 maverick | Fixed 3.1.7+build3+nobinonly-0ubuntu0.10.10.1 |
| 10.04 LTS lucid | Fixed 3.1.7+build3+nobinonly-0ubuntu0.10.04.1 |
| 9.10 karmic | Ignored end of life |
| 8.04 LTS hardy | Ignored end of life |
| 6.06 LTS dapper | Not in release |
| thunderbird-locales | 11.04 natty | Not affected |
| 10.10 maverick | Not affected |
| 10.04 LTS lucid | Not affected |
| 9.10 karmic | Not affected |
| 8.04 LTS hardy | Not affected |
| 6.06 LTS dapper | Not affected |
| xulrunner-1.9.1 | 11.04 natty | Not in release |
| 10.10 maverick | Not in release |
| 10.04 LTS lucid | Not in release |
| 9.10 karmic | Fixed 1.9.1.16+build2+nobinonly-0ubuntu0.9.10.1 |
| 8.04 LTS hardy | Not in release |
| 6.06 LTS dapper | Not in release |
| xulrunner-1.9.2 | 11.04 natty | Fixed 1.9.2.13+build3+nobinonly-0ubuntu1 |
| 10.10 maverick | Fixed 1.9.2.13+build3+nobinonly-0ubuntu0.10.10.1 |
| 10.04 LTS lucid | Fixed 1.9.2.13+build3+nobinonly-0ubuntu0.10.04.1 |
| 9.10 karmic | Fixed 1.9.2.13+build3+nobinonly-0ubuntu0.9.10.1 |
| 8.04 LTS hardy | Fixed 1.9.2.13+build3+nobinonly-0ubuntu0.8.04.1 |
| 6.06 LTS dapper | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [jdstrand](https://launchpad.net/~jdstrand)

Ubuntu 11.04 (Natty Narwhal) has 4.0b7. Fixes will be in 4.0b8.
new version of thunderbird-locales updated for Lucid

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3776)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2010-3776)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2010-3776)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2010-3776)

### Related Ubuntu Security Notices (USN)

+ [USN-1123-1](https://usn.ubuntu.com/USN-1123-1)
+ Xulrunner vulnerabilities
+ 30 April 2011

+ [USN-1020-1](https://usn.ubuntu.com/USN-1020-1)
+ Thunderbird vulnerabilities
+ 9 December 2010

+ [USN-1019-1](https://usn.ubuntu.com/USN-1019-1)
+ Firefox and Xulrunner vulnerabilities
+ 9 December 2010

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2010-3776>
