SB2023100508 - Multiple vulnerabilities in Google Android 14



SB2023100508 - Multiple vulnerabilities in Google Android 14

Published: October 5, 2023 Updated: May 5, 2025

Security Bulletin ID SB2023100508
Severity
High
Patch available
YES
Number of vulnerabilities 110
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 3% Low 97%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 110 secuirty vulnerabilities.


1) Information exposure (CVE-ID: CVE-2023-21394)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the System component. A local application can gain access to sensitive information.


2) Improper input validation (CVE-ID: CVE-2023-21388)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the System component. A local application can execute arbitrary code.


3) Improper input validation (CVE-ID: CVE-2023-21380)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the System component. A local application can execute arbitrary code.


4) Improper input validation (CVE-ID: CVE-2023-21378)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the System component. A local application can execute arbitrary code.


5) Improper input validation (CVE-ID: CVE-2023-21376)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the System component. A local application can execute arbitrary code.


6) Improper input validation (CVE-ID: CVE-2023-21375)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the System component. A local application can execute arbitrary code.


7) Improper input validation (CVE-ID: CVE-2023-21373)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the System component. A local application can execute arbitrary code.


8) Improper input validation (CVE-ID: CVE-2023-21371)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the System component. A local application can execute arbitrary code.


9) Improper input validation (CVE-ID: CVE-2023-21370)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the System component. A local application can execute arbitrary code.


10) Improper input validation (CVE-ID: CVE-2023-21360)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the System component. A local application can execute arbitrary code.


11) Improper input validation (CVE-ID: CVE-2023-21310)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the System component. A local application can execute arbitrary code.


12) Improper input validation (CVE-ID: CVE-2023-21356)

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper input validation within the System component. A remote attacker can trick the victim to open a specially crafted file and execute arbitrary code.


13) Information exposure (CVE-ID: CVE-2023-21315)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the System component. A local application can gain access to sensitive information.


14) Improper input validation (CVE-ID: CVE-2023-21390)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the System component. A local application can execute arbitrary code.


15) Information exposure (CVE-ID: CVE-2023-21312)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the System component. A local application can gain access to sensitive information.


16) Improper input validation (CVE-ID: CVE-2023-21392)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the System component. A local application can execute arbitrary code.


17) Improper input validation (CVE-ID: CVE-2023-21361)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the System component. A local application can execute arbitrary code.


18) Improper input validation (CVE-ID: CVE-2023-21358)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the System component. A local application can execute arbitrary code.


19) Improper input validation (CVE-ID: CVE-2023-21313)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the System component. A local application can execute arbitrary code.


20) Improper input validation (CVE-ID: CVE-2021-39810)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the System component. A local application can execute arbitrary code.


21) Improper input validation (CVE-ID: CVE-2023-21355)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the Media Framework component. A local application can execute arbitrary code.


22) Improper input validation (CVE-ID: CVE-2023-21381)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the Media Framework component. A local application can execute arbitrary code.


23) Information exposure (CVE-ID: CVE-2023-21345)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


24) Improper input validation (CVE-ID: CVE-2023-21339)

The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the Framework component. A local application can perform a denial of service (DoS) attack.


25) Information exposure (CVE-ID: CVE-2023-21387)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


26) Improper input validation (CVE-ID: CVE-2023-21389)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the System component. A local application can execute arbitrary code.


27) Improper input validation (CVE-ID: CVE-2023-21393)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the System component. A local application can execute arbitrary code.


28) Information exposure (CVE-ID: CVE-2023-21377)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


29) Information exposure (CVE-ID: CVE-2023-21368)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the System component. A local application can gain access to sensitive information.


30) Information exposure (CVE-ID: CVE-2023-21307)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the System component. A local application can gain access to sensitive information.


31) Information exposure (CVE-ID: CVE-2023-21297)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the System component. A local application can gain access to sensitive information.


32) Information exposure (CVE-ID: CVE-2023-21386)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the System component. A local application can gain access to sensitive information.


33) Improper input validation (CVE-ID: CVE-2023-21391)

The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the System component. A local application can perform a denial of service (DoS) attack.


34) Improper input validation (CVE-ID: CVE-2023-21369)

The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the System component. A local application can perform a denial of service (DoS) attack.


35) Improper input validation (CVE-ID: CVE-2023-21311)

The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the System component. A local application can perform a denial of service (DoS) attack.


36) Information exposure (CVE-ID: CVE-2023-21395)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the System component. A local application can gain access to sensitive information.


37) Information exposure (CVE-ID: CVE-2023-21385)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the System component. A local application can gain access to sensitive information.


38) Information exposure (CVE-ID: CVE-2023-21384)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the System component. A local application can gain access to sensitive information.


39) Information exposure (CVE-ID: CVE-2023-21383)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the System component. A local application can gain access to sensitive information.


40) Information exposure (CVE-ID: CVE-2023-21379)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the System component. A local application can gain access to sensitive information.


41) Information exposure (CVE-ID: CVE-2023-21359)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the System component. A local application can gain access to sensitive information.


42) Improper input validation (CVE-ID: CVE-2023-21396)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the System component. A local application can execute arbitrary code.


43) Information exposure (CVE-ID: CVE-2023-21357)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the System component. A local application can gain access to sensitive information.


44) Information exposure (CVE-ID: CVE-2023-21353)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the System component. A local application can gain access to sensitive information.


45) Information exposure (CVE-ID: CVE-2023-21352)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the System component. A local application can gain access to sensitive information.


46) Information exposure (CVE-ID: CVE-2023-21350)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the System component. A local application can gain access to sensitive information.


47) Information exposure (CVE-ID: CVE-2023-21347)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the System component. A local application can gain access to sensitive information.


48) Information exposure (CVE-ID: CVE-2023-21340)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the System component. A local application can gain access to sensitive information.


49) Information exposure (CVE-ID: CVE-2023-21335)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the System component. A local application can gain access to sensitive information.


50) Information exposure (CVE-ID: CVE-2023-21325)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the System component. A local application can gain access to sensitive information.


51) Information exposure (CVE-ID: CVE-2023-21314)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the System component. A local application can gain access to sensitive information.


52) Information exposure (CVE-ID: CVE-2023-21308)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the System component. A local application can gain access to sensitive information.


53) Information exposure (CVE-ID: CVE-2022-20531)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the System component. A local application can gain access to sensitive information.


54) Information exposure (CVE-ID: CVE-2023-21382)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


55) Information exposure (CVE-ID: CVE-2023-21354)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


56) Integer overflow (CVE-ID: CVE-2022-29824)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*). A remote attacker can pass specially crafted multi-gigabyte XML file to the application, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


57) Improper input validation (CVE-ID: CVE-2023-21298)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the Framework component. A local application can execute arbitrary code.


58) Information exposure (CVE-ID: CVE-2023-21294)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


59) Information exposure (CVE-ID: CVE-2023-21293)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


60) Out-of-bounds write (CVE-ID: CVE-2022-27404)

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted input in the "sfnt_init_face" function. A remote attacker can trigger out-of-bounds write and execute arbitrary code on the target system.


61) Information exposure (CVE-ID: CVE-2022-20264)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


62) Improper input validation (CVE-ID: CVE-2023-21397)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the Framework component. A local application can execute arbitrary code.


63) Improper input validation (CVE-ID: CVE-2023-21374)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the Framework component. A local application can execute arbitrary code.


64) Improper input validation (CVE-ID: CVE-2023-21341)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the Framework component. A local application can execute arbitrary code.


65) Improper input validation (CVE-ID: CVE-2023-21338)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the Framework component. A local application can execute arbitrary code.


66) Improper input validation (CVE-ID: CVE-2023-21337)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the Framework component. A local application can execute arbitrary code.


67) Improper input validation (CVE-ID: CVE-2023-21328)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the Framework component. A local application can execute arbitrary code.


68) Improper input validation (CVE-ID: CVE-2023-21324)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the Framework component. A local application can execute arbitrary code.


69) Improper input validation (CVE-ID: CVE-2023-21365)

The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the Framework component. A local application can perform a denial of service (DoS) attack.


70) Information exposure (CVE-ID: CVE-2023-21296)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


71) Improper input validation (CVE-ID: CVE-2023-21364)

The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the Framework component. A local application can perform a denial of service (DoS) attack.


72) Improper input validation (CVE-ID: CVE-2023-21362)

The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the Framework component. A local application can perform a denial of service (DoS) attack.


73) Improper input validation (CVE-ID: CVE-2023-21398)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the Framework component. A local application can execute arbitrary code.


74) Improper input validation (CVE-ID: CVE-2023-21351)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the Framework component. A local application can execute arbitrary code.


75) Improper input validation (CVE-ID: CVE-2023-21343)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the Framework component. A local application can execute arbitrary code.


76) Improper input validation (CVE-ID: CVE-2023-21342)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the Framework component. A local application can execute arbitrary code.


77) Information exposure (CVE-ID: CVE-2023-40101)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Android runtime component. A local application can gain access to sensitive information.


78) Improper input validation (CVE-ID: CVE-2023-21372)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the Android runtime component. A local application can execute arbitrary code.


79) Information exposure (CVE-ID: CVE-2023-21367)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Android runtime component. A local application can gain access to sensitive information.


80) Information exposure (CVE-ID: CVE-2023-21366)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Android runtime component. A local application can gain access to sensitive information.


81) Information exposure (CVE-ID: CVE-2023-21309)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Android runtime component. A local application can gain access to sensitive information.


82) Information exposure (CVE-ID: CVE-2023-21295)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


83) Information exposure (CVE-ID: CVE-2023-21299)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


84) Information exposure (CVE-ID: CVE-2023-21349)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


85) Information exposure (CVE-ID: CVE-2023-21326)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


86) Information exposure (CVE-ID: CVE-2023-21348)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


87) Information exposure (CVE-ID: CVE-2023-21346)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


88) Information exposure (CVE-ID: CVE-2023-21344)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


89) Information exposure (CVE-ID: CVE-2023-21336)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


90) Information exposure (CVE-ID: CVE-2023-21334)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


91) Information exposure (CVE-ID: CVE-2023-21333)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


92) Information exposure (CVE-ID: CVE-2023-21332)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


93) Information exposure (CVE-ID: CVE-2023-21331)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


94) Information exposure (CVE-ID: CVE-2023-21330)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


95) Information exposure (CVE-ID: CVE-2023-21329)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


96) Information exposure (CVE-ID: CVE-2023-21327)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


97) Information exposure (CVE-ID: CVE-2023-21323)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


98) Information exposure (CVE-ID: CVE-2023-21300)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


99) Information exposure (CVE-ID: CVE-2023-21321)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


100) Information exposure (CVE-ID: CVE-2023-21320)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


101) Information exposure (CVE-ID: CVE-2023-21319)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


102) Information exposure (CVE-ID: CVE-2023-21318)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


103) Information exposure (CVE-ID: CVE-2023-21317)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


104) Information exposure (CVE-ID: CVE-2023-21316)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


105) Information exposure (CVE-ID: CVE-2023-21306)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


106) Information exposure (CVE-ID: CVE-2023-21305)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


107) Information exposure (CVE-ID: CVE-2023-21304)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


108) Information exposure (CVE-ID: CVE-2023-21303)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


109) Information exposure (CVE-ID: CVE-2023-21302)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


110) Information exposure (CVE-ID: CVE-2023-21301)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Framework component. A local application can gain access to sensitive information.


Remediation

Install update from vendor's website.