CVE-2016-7153
06.09.2016, 10:59
The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.Enginsight
Vendor | Product | Version |
---|---|---|
microsoft | edge | - |
microsoft | internet_explorer | - |
chrome | - | |
apple | safari | * |
opera | opera_browser | - |
mozilla | firefox | * |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
chromium-browser |
| ||||||||||
firefox |
| ||||||||||
oxide-qt |
| ||||||||||
thunderbird |
|
Common Weakness Enumeration
References