Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-7153

Опубликовано: 06 сент. 2016
Источник: nvd
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:internet_explorer:-:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:google:chrome:-:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
Конфигурация 4
cpe:2.3:a:opera:opera_browser:-:*:*:*:*:*:*:*
Конфигурация 5
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*

EPSS

Процентиль: 79%
0.01253
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 9 лет назад

The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

CVSS3: 3.1
redhat
больше 9 лет назад

The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

CVSS3: 5.3
debian
больше 9 лет назад

The HTTP/2 protocol does not consider the role of the TCP congestion w ...

CVSS3: 5.3
github
больше 3 лет назад

The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

EPSS

Процентиль: 79%
0.01253
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200