Attackers can exploit these issues to execute arbitrary code in the context of the browser, cause denial-of-service conditions, and disclose sensitive information; other attacks are also possible.
A secure session that relies solely on secure cookies for identifying the session can possibly be hijacked, or an account which relies solely on secure cookies for logging on may be compromised, by an attacker who manages to eavesdrop on the unencrypted network connection.