The SPDY protocol 3 and earlier, as used in Mozilla Firefox, Google Chrome, and other products, can perform TLS encryption of compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing length differences during a series of guesses in which a string in an HTTP request potentially matches an unknown string in an HTTP header, aka a "CRIME" attack.
CVSS Details
- CVSS 3.1 Base Score: 3.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Apr 29, 2015 |
| Google Chrome | — | — | Dec 7, 2012 | Sep 15, 2012 |
| Mfsa2012 73 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 15.0 | Oct 23, 2012 | Sep 15, 2012 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.12.0 | Oct 23, 2012 | Sep 15, 2012 |
| Ubuntu | — | Upgrade chromium-browserUpgrade firefox | Nov 19, 2024 | Sep 15, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub