CVE-2016-7152
Last modified
CVE-2016-7152 is a vulnerability of currently unknown severity. The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.. EPSS estimates a 13.98% chance of exploitation in the next 30 days.
Description
The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Opera | Opera | All versions |
| Apple | Safari | All versions |
| Mozilla | Firefox | All versions |
| Microsoft | Edge | All versions |
| Microsoft | Internet Explorer | All versions |
| Chrome | All versions |
References
- https://tom.vg/papers/heist_blackhat2016.pdfTechnical Description
- https://tom.vg/papers/heist_blackhat2016.pdfTechnical Description
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-7152?
How severe is CVE-2016-7152?
How do I fix CVE-2016-7152?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-7146MoinMoin 1.9.8 allows remote attackers to conduct "JavaScrip…
- CVE-2016-7147Cross-site scripting (XSS) vulnerability in the manage_findR…
- CVE-2016-7148MoinMoin 1.9.8 allows remote attackers to conduct "JavaScrip…
- CVE-2016-7149Cross-site scripting (XSS) vulnerability in b2evolution 6.7.…
- CVE-2016-7150Cross-site scripting (XSS) vulnerability in b2evolution 6.7.…
- CVE-2016-7151Capstone 3.0.4 has an out-of-bounds vulnerability (SEGV caus…
- CVE-2016-7153The HTTP/2 protocol does not consider the role of the TCP co…
- CVE-2016-7154Use-after-free vulnerability in the FIFO event channel code …
- CVE-2016-7155hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows loc…4.4
- CVE-2016-7156The pvscsi_convert_sglist function in hw/scsi/vmw_pvscsi.c i…4.4
- CVE-2016-7157The (1) mptsas_config_manufacturing_1 and (2) mptsas_config_…4.4
- CVE-2016-7160A vulnerability on Samsung Mobile M(6.0) devices exists beca…
Are you affected by CVE-2016-7152?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
