CVE-2016-7153
06.09.2016, 10:59
The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.Enginsight
| Vendor | Product | Version |
|---|---|---|
| microsoft | edge | - |
| microsoft | internet_explorer | - |
| chrome | - | |
| apple | safari | * |
| opera | opera_browser | - |
| mozilla | firefox | * |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| chromium-browser |
| ||||||||||
| firefox |
| ||||||||||
| oxide-qt |
| ||||||||||
| thunderbird |
|
Common Weakness Enumeration
References