ZeroHour

CVE-2016-7152

CVSS 3.0
5.3 medium
EPSS
14%p96
Published
()
Modified
Description

The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

Vendors
operaapplemozillamicrosoftgoogle
Products
opera, safari, firefox, edge, internet explorer, chrome
Weakness
CWE-200
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.