tif_pixarlog.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in heap allocated buffers. Reported as MSVR 35094, aka "PixarLog horizontalDifference heap-buffer-overflow."
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-9533.json"