processCropSelections in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based buffer overflow (e.g., "WRITE of size 307203") via a crafted TIFF image.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-48281.json"