Description
Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability involves the DOM copy‑and‑paste and drag‑and‑drop components of Firefox and Thunderbird. An attacker could manipulate or inject data during clipboard operations. While the CVE entry does not state which data types are affected, it can be inferred that the altered or injected content might be processed by the application.

Affected Systems

Mozilla Firefox and Mozilla Thunderbird versions earlier than 153 are vulnerable. Users running these older releases could be exposed until they upgrade to the fixed version.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.5, indicating high severity, but its EPSS score is below 1%, suggesting a low probability of exploitation at present. It is not listed in the CISA KEV catalog. The attack vector is not explicitly stated, but the nature of the flaw implies it could be triggered via local user interactions, such as a malicious web page or email that uses copy, paste, or drag‑and‑drop operations; this inference is based solely on the description of the component affected.

Generated by OpenCVE AI on August 5, 2026 at 02:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Mozilla Firefox 153 or later
  • Upgrade to Mozilla Thunderbird 153 or later
  • Disable or restrict clipboard and drag‑and‑drop functionality in the affected applications until a patch is applied

Generated by OpenCVE AI on August 5, 2026 at 02:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 00:15:00 +0000


Wed, 22 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153. Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
References

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 21 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153.
Title Other issue in the DOM: Copy & Paste and Drag & Drop component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-22T19:18:40.219Z

Reserved: 2026-07-20T21:56:44.836Z

Link: CVE-2026-16378

cve-icon Vulnrichment

Updated: 2026-07-22T17:07:43.096Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T13:17:12.967

Modified: 2026-07-24T16:39:21.980

Link: CVE-2026-16378

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-21T12:37:52Z

Links: CVE-2026-16378 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:15:03Z

Weaknesses
  • CWE-20

    Improper Input Validation