Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ok File Formats Project

First CVE: —Active for: N/ATotal CVEs: 14

The Ok File Formats Project maintains a focused library for parsing and handling file formats, and despite its narrow product scope sits among the more prominent entities in the vulnerability landscape due to its foundational role in downstream software that processes structured data. The disclosed vulnerabilities reflect the parsing complexity inherent to file-format handling, where input validation and codec implementation present recurring attack surface. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
4.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ok File Formats Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2018
7 years ago
Most Recent CVE
Jun 15, 2022
1,504 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-28233HIGH
Heap-based Buffer Overflow vulnerability exists in ok-file-formats 1 via the ok_jpg_generate_huffman_table function in ok_jpg.c.
Aug 27, 20218.827NONO
CVE-2018-20618HIGH
ok-file-formats through 2018-10-16 has a heap-based buffer over-read in the ok_mo_decode2 function in ok_mo.c.
Dec 31, 20188.827NONO
CVE-2018-20617HIGH
ok-file-formats through 2018-10-16 has a heap-based buffer overflow in the ok_csv_decode2 function in ok_csv.c.
Dec 31, 20188.827NONO
CVE-2018-20616HIGH
ok-file-formats through 2018-10-16 has a heap-based buffer overflow in the ok_wav_decode_ms_adpcm_data function in ok_wav.c.
Dec 31, 20188.827NONO
CVE-2021-41413HIGH
ok-file-formats master 2021-9-12 is affected by a buffer overflow in ok_jpg_convert_data_unit_grayscale and ok_jpg_convert_YCbCr_to_RGB.
Jun 15, 20227.825NONO
CVE-2021-44343HIGH
David Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurred in function ok_pn
Mar 3, 20227.825NONO
CVE-2021-44335HIGH
David Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurs in function ok_png_
Mar 3, 20227.825NONO
CVE-2021-44342HIGH
David Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow via function ok_png_transform_scanline() in "/ok_png.c:494".
Feb 28, 20227.824NONO
CVE-2021-44340HIGH
David Brackeen ok-file-formats dev version is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurred in function o
Feb 28, 20227.824NONO
CVE-2021-44334HIGH
David Brackeen ok-file-formats 97f78ca is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurs in function ok_jpg_
Feb 28, 20227.824NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
14%
86%
Severity distribution among all CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local8 (57.1%)
Network6 (42.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required14 (100.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None14 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ok File Formats Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ok File Formats Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ok File Formats Project's Products

View all 1 CNAs →

Top CWEs