LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cause a denial of service (crash) via a crafted TIFF file.
https://www.exploit-db.com/exploits/42301/
https://usn.ubuntu.com/3606-1/
http://www.securityfocus.com/bid/98594