VDB
CVE-2024-9506
CVE-2024-9506
PUBLISHED
CVSS 3.700000047683716 LOW
Improper regular expression in Vue's parseHTML function leads to a potential regular expression denial of service vulnerability.
EPSS 0.53% · 42.4th percentile
Risk Scores
CVSS 3.1
3.700000047683716
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS Score
0.53%
42.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| vue | vue | 2.0.0 |
| npm | vue | 2.0.0-alpha.1 |
Timeline
- Oct 15, 2024 CVE Published
- Oct 16, 2024 EPSS Score
- Oct 16, 2024 Coalition ESS Score
- Oct 24, 2024 CVE Updated
- Nov 4, 2024 EPSS Score
- Nov 22, 2024 EPSS Score
- Dec 12, 2024 EPSS Score
- Dec 31, 2024 EPSS Score
- Jan 19, 2025 EPSS Score
- Feb 6, 2025 EPSS Score
- Feb 25, 2025 EPSS Score
- Mar 16, 2025 EPSS Score