ZeroHour

CVE-2016-7153

CVSS 3.0
5.3 medium
EPSS
14%p96
Published
()
Modified
Description

The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

Vendors
microsoftgoogleappleoperamozilla
Products
edge, internet explorer, chrome, safari, opera browser, firefox
Weakness
CWE-200
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.