Security Advisory

CVE-2022-40983

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-01-12 16:44:11
Last updated 2025-03-05 19:35:47
Assigner talos
State PUBLISHED

Description

An integer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2. A specially-crafted javascript code can trigger an integer overflow during memory allocation, which can lead to arbitrary code execution. Target application would need to access a malicious web page to trigger this vulnerability.