AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2015-3167

HIGH · CVSS 7.5 EPSS 4.13%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-11-20 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2015-3167
Severity
HIGH
CVSS
7.5
EPSS
4.13%

Original Filing — NVD Description

contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack.