CVE-2022-40983: Integer Overflow
An integer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2. A specially-crafted javascript code can trigger an integer overflow during memory allocation, which can lead to arbitrary code execution. Target application would need to access a malicious web page to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-40983?
CVE-2022-40983 is an integer overflow vulnerability in the QML QtScript Reflect API of Qt Project Qt 6.3.2.
How does CVE-2022-40983 work?
CVE-2022-40983 can be triggered by a specially-crafted javascript code that causes an integer overflow during memory allocation, potentially leading to arbitrary code execution.
What is the severity of CVE-2022-40983?
CVE-2022-40983 has a severity rating of 8.8 (high).
Which software versions are affected by CVE-2022-40983?
Qt Project Qt 6.3.2 is affected by CVE-2022-40983.
How can CVE-2022-40983 be mitigated?
To mitigate CVE-2022-40983, update Qt Project to a version that has a fix for the vulnerability.