The Ok File Formats Project maintains a focused library for parsing and handling file formats, and despite its narrow product scope sits among the more prominent entities in the vulnerability landscape due to its foundational role in downstream software that processes structured data. The disclosed vulnerabilities reflect the parsing complexity inherent to file-format handling, where input validation and codec implementation present recurring attack surface. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ok File Formats Project over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-28233HIGH Heap-based Buffer Overflow vulnerability exists in ok-file-formats 1 via the ok_jpg_generate_huffman_table function in ok_jpg.c. | Aug 27, 2021 | 8.8 | 27 | NO | NO |
CVE-2018-20618HIGH ok-file-formats through 2018-10-16 has a heap-based buffer over-read in the ok_mo_decode2 function in ok_mo.c. | Dec 31, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-20617HIGH ok-file-formats through 2018-10-16 has a heap-based buffer overflow in the ok_csv_decode2 function in ok_csv.c. | Dec 31, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-20616HIGH ok-file-formats through 2018-10-16 has a heap-based buffer overflow in the ok_wav_decode_ms_adpcm_data function in ok_wav.c. | Dec 31, 2018 | 8.8 | 27 | NO | NO |
CVE-2021-41413HIGH ok-file-formats master 2021-9-12 is affected by a buffer overflow in ok_jpg_convert_data_unit_grayscale and ok_jpg_convert_YCbCr_to_RGB. | Jun 15, 2022 | 7.8 | 25 | NO | NO |
CVE-2021-44343HIGH David Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurred in function ok_pn | Mar 3, 2022 | 7.8 | 25 | NO | NO |
CVE-2021-44335HIGH David Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurs in function ok_png_ | Mar 3, 2022 | 7.8 | 25 | NO | NO |
CVE-2021-44342HIGH David Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow via function ok_png_transform_scanline() in "/ok_png.c:494". | Feb 28, 2022 | 7.8 | 24 | NO | NO |
CVE-2021-44340HIGH David Brackeen ok-file-formats dev version is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurred in function o | Feb 28, 2022 | 7.8 | 24 | NO | NO |
CVE-2021-44334HIGH David Brackeen ok-file-formats 97f78ca is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurs in function ok_jpg_ | Feb 28, 2022 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ok File Formats Project.
Media articles that mention a CVE ID that affects a product developed by Ok File Formats Project — matched by CVE ID, not by vendor name.