{"api_version":"1","generated_at":"2026-07-23T06:11:25+00:00","cve":"CVE-2008-5109","urls":{"html":"https://cve.report/CVE-2008-5109","api":"https://cve.report/api/cve/CVE-2008-5109.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-5109","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-5109"},"summary":{"title":"CVE-2008-5109","description":"The default configuration of Adobe Flash Media Server (FMS) 3.0 does not enable SWF Verification for (1) RTMPE and (2) RTMPTE sessions, which makes it easier for remote attackers to make copies of video content via stream-capture software.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-11-25 23:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-16","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/32771","name":"http://secunia.com/advisories/32771","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Flash Media Server Video Stream Capture Security Issue - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/49952","name":"http://www.osvdb.org/49952","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.adobe.com/support/security/advisories/apsa08-11.html","name":"http://www.adobe.com/support/security/advisories/apsa08-11.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Adobe - Security Advisories : APSA08-11 - Content Protection in Flash Media Server 3.0","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-5109","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-5109","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"5109","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"flash_media_server","cpe6":"3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"5109","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"flash_media_server","cpe6":"3.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T10:40:17.175Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"32771","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32771"},{"name":"49952","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/49952"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.adobe.com/support/security/advisories/apsa08-11.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"The default configuration of Adobe Flash Media Server (FMS) 3.0 does not enable SWF Verification for (1) RTMPE and (2) RTMPTE sessions, which makes it easier for remote attackers to make copies of video content via stream-capture software."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2008-11-25T23:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"32771","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32771"},{"name":"49952","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/49952"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.adobe.com/support/security/advisories/apsa08-11.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-5109","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The default configuration of Adobe Flash Media Server (FMS) 3.0 does not enable SWF Verification for (1) RTMPE and (2) RTMPTE sessions, which makes it easier for remote attackers to make copies of video content via stream-capture software."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"32771","refsource":"SECUNIA","url":"http://secunia.com/advisories/32771"},{"name":"49952","refsource":"OSVDB","url":"http://www.osvdb.org/49952"},{"name":"http://www.adobe.com/support/security/advisories/apsa08-11.html","refsource":"CONFIRM","url":"http://www.adobe.com/support/security/advisories/apsa08-11.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-5109","datePublished":"2008-11-25T23:00:00.000Z","dateReserved":"2008-11-17T00:00:00.000Z","dateUpdated":"2024-09-16T16:57:53.116Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-11-25 23:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-16","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:flash_media_server:3.0:*:*:*:*:*:*:*","matchCriteriaId":"EE4A07B6-E5DA-4781-ABB3-DB2663E2A737"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:flash_media_server:3.5:*:*:*:*:*:*:*","matchCriteriaId":"897B12DA-8749-44F7-AA1E-AB1F01BB205E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"5109","Ordinal":"1","Title":"CVE-2008-5109","CVE":"CVE-2008-5109","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"5109","Ordinal":"1","NoteData":"The default configuration of Adobe Flash Media Server (FMS) 3.0 does not enable SWF Verification for (1) RTMPE and (2) RTMPTE sessions, which makes it easier for remote attackers to make copies of video content via stream-capture software.","Type":"Description","Title":"CVE-2008-5109"},{"CveYear":"2008","CveId":"5109","Ordinal":"2","NoteData":"2008-11-25","Type":"Other","Title":"Published"}]}}}