CVE-2018-20618: Ok-File-Formats Project Ok-File-Formats

High severity, CVSS 8.8. EPSS: 1.4% chance of exploitation in the next 30 days.

ok-file-formats through 2018-10-16 has a heap-based buffer over-read in the ok_mo_decode2 function in ok_mo.c.

Affected products

Published 2018-12-31. Last modified 2026-06-17.