Vulnerability · NVD
CVE-2016-7152
CVE-2016-7152, medium severity (CVSS 5.3): 5 tracked apps concerned, all fixed or indeterminable on their current version.
- Severity (CVSS)
- 5.3
- Exploitation
- 14.0 %
- Tracked apps
- 5
- Still exposed
- 0
NVD scale
EPSS, predicted over 30 days
The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.
Attack vector : Network
No privileges required
No user interaction
Show raw CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
13.98%
moderate exploit risk
percentile 96.3%
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
-
Affected - Fixed in - Latest tracked - undetermined
-
Affected - Fixed in - Latest tracked - undetermined
-
-
-
Vulnerable CPE configurations (5)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
| apple |
safari All platforms (wildcard)
|
All platforms (wildcard) | - | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* |
| mozilla |
firefox All platforms (wildcard)
|
All platforms (wildcard) | - | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
| microsoft |
edge All platforms (wildcard)
|
All platforms (wildcard) | - | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
|
chrome All platforms (wildcard)
|
All platforms (wildcard) | - | cpe:2.3:a:google:chrome:-:*:*:*:*:*:*:* | |
|
chrome All platforms (wildcard)
|
All platforms (wildcard) | - | cpe:2.3:a:google:chrome:-:*:*:*:*:*:*:* |