CVE-2009-1365
Summary
| CVE | CVE-2009-1365 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-05-01 17:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Unspecified vulnerability in Adobe Flash Media Server (FMS) before 3.0.4 and 3.5.x before 3.5.2, as used in Flash Media Interactive Server and Flash Media Streaming Server, allows remote attackers to execute arbitrary remote procedures within an ActionScript file on the server via RPC requests. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Adobe | Flash Media Server | 2.0.1 | All | All | All |
| Application | Adobe | Flash Media Server | 2.0.2 | All | All | All |
| Application | Adobe | Flash Media Server | 2.0.3 | All | All | All |
| Application | Adobe | Flash Media Server | 2.0.4 | All | All | All |
| Application | Adobe | Flash Media Server | 2.0.5 | All | All | All |
| Application | Adobe | Flash Media Server | 3.0 | All | All | All |
| Application | Adobe | Flash Media Server | 3.0.1 | All | All | All |
| Application | Adobe | Flash Media Server | 3.0.2 | All | All | All |
| Application | Adobe | Flash Media Server | 3.5 | All | All | All |
| Application | Adobe | Flash Media Server | 3.5.1 | All | All | All |
| Application | Adobe | Flash Media Server | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Adobe - Security Advisories : APSB09-05 - Updates available to address Flash Media Server privilege escalation issue | af854a3a-2127-422b-91ae-364da2661108 | www.adobe.com | Patch, Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Adobe Flash Media Server Unspecified RPC Call Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| Adobe Flash Media Server RPC Security Bypass Vulnerability - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Adobe Flash Media Server Bug Lets Remote Users Execute Remote Procedures - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.