← All CVEs

CVE-2016-7152

medium · 5.3

The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

5.3
CVSS
14.0%
EPSS (exploit prob.)
96th
EPSS percentile
2016-09-06
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Weaknesses

CWE-200

Affected products

VendorProductAffected versions
operaoperaall versions
applesafariall versions
mozillafirefoxall versions
microsoftedgeall versions
microsoftinternet_explorerall versions
googlechromeall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-7152