AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2016-7152

MEDIUM · CVSS 5.3 EPSS 13.98%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2016-09-06 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2016-7152
Severity
MEDIUM
CVSS
5.3
EPSS
13.98%

Original NVD Description

The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.