A read outside of array in tiffsplit (or other utilities using TIFFNumberOfStrips()) (CVE-2016-9273).
A potential read outside buffer in _TIFFPrintField() (CVE-2016-9297).
Multiple uint32 overflows in writeBufferToSeparateStrips(), writeBufferToContigTiles() and writeBufferToSeparateTiles() that could cause heap buffer overflows (CVE-2016-9532).