Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.7
CVE-2026-16097: Shibby Tomato Scheduler Name Handler stack overflow risk
CVE-2026-16097
CVE-2026-16097
Summary
The Shibby Tomato 1.28 Scheduler Name Handler has a vulnerability that could allow an attacker to overflow the system's memory, potentially leading to system crashes or unauthorized access. This issue is especially concerning because it can be exploited remotely, giving an attacker more flexibility. If you're using Shibby Tomato, consider updating to the more recent FreshTomato alternative, which is likely to be more secure.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| shibby | tomato | 1.28 |
Original title
A vulnerability was found in Shibby Tomato 1.28. This vulnerability affects the function sub_42537C of the component Scheduler Name Handler. The manipulation of the argument a1 results in stack-bas...
Original description
A vulnerability was found in Shibby Tomato 1.28. This vulnerability affects the function sub_42537C of the component Scheduler Name Handler. The manipulation of the argument a1 results in stack-based buffer overflow. It is possible to launch the attack remotely. This project is superseded by FreshTomato.
nvd CVSS2.0
9.0
nvd CVSS3.1
8.8
nvd CVSS4.0
8.7
Vulnerability type
CWE-119
Buffer Overflow
CWE-121
Stack-based Buffer Overflow
Published: 18 Jul 2026 · Updated: 20 Jul 2026 · First seen: 18 Jul 2026